
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 48
HardenedWindows2000
PerfectingtheWindow s2000 Installation
Firstofall,installthelatestservicepack.Atthetimeofthiswriting,SP2isthelatest
availableversion.Infact,ISAwillnotinstallunlessyouhaveappliedSP1attheleast.
MicrosoftoffersWindows2000servicepacksviathisURL:
http://www.microsoft.com/windows2000/downloads/servicepacks/default.asp
Additionally,thesecurityupdatesavailableat
http://www.microsoft.com/windows2000/downloads/security/default.aspshouldbe
applied.
Hardeni ngtheConfiguration
Thebasicideasbehindthehardeningstrategyarealwaysthesame:
n Removeunusednetworkservices.
n DisableNetBIOS.
n ConfigureIPRouting.
n Disableunusedservices.
n Strengthentheaccountandauditsettings.
n Removeunusedandpotentiallydangerouscomponents.
n Gothroughallthefilesystempermissionsettings.
Windows2000nativelyencryptsitsaccountdatabase,avoidingtheneedtomanually
runsyskey.PhilipCoxinhisarticle“HardeningWindows2000”doessuggestthatwe
furtherrunSyskeytoenforcetheuseofmanualpasswordentrytoaccessthe
decryptionkey
12
.
12
http://www.sysexp.com/win2k/HardenWin2K.html
Comentarios a estos manuales