
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 45
enhancedsecurityagainst"passwordguessing" or "dictionaryattacks"byoutside
intruders.…The Passfilt.dllfileimplementsthefollowingpasswordpolicy:
n Passwordsmustbeatleastsix(6)characterslong.
n Passwordsmustcontaincharactersfromatleastthree(3)ofthefollowingfour
(4)classes:
1. Englishuppercaseletters A,B,C,...Z
2. Englishlowercaseletters a,b,c,...z
3. WesternizedArabicnumerals 0,1,2,...9
4. Nonalphanumeric("specialcharacters")suchaspunctuationsymbols
n Passwordsmaynotcontainyourusernameoranypartofyourfullname.
TheserequirementsarehardcodedinthePassfilt.dllfileandcannotbechanged
throughtheuserinterfaceorregistry.Ifyouwishtoraise orlowertheserequirements,
youmustwriteyourown.dllandimplementitinthesamefashionastheMicrosoft
versionthatisavailablewithWindowsNT4.0ServicePack2.”
10
Anidealauditpolicyshouldincludetheelementsbelow:
n AuditaccountmanagementSuccess:Failure
n AuditlogoneventsSuccess:Failure
n Auditobjectaccess:Failure
n AuditpolicychangeSuccess:Failure
n Auditprivilegeuse:Failure
n Auditprocesstracking:Noauditing
n AuditsystemeventsSuccess:Failure
Additionally,removeanyunnecessaryuseraccounts.Intheory,asingleuseraccount
fortheadministratorissufficient.Renamethisaccounttosomethinghardtoguess.
Thoroughlycheckthesystem’spermissionsettingsandensurethatnooneelseexcept
therenamedadministratorcanhaveaccess.
FINALLY,donotforgettotightenthefilesystemACLsettings.Thepolicyfilesand
thelogfilesshouldnotbeaccessibletothegeneralusersoranyunauthorizedservice.
10
http://support.microsoft.com/default.aspx?scid=kb;ENUS;q161990
Kommentare zu diesen Handbüchern