
YuChakTinMichael‘sGIACGCFWProjectAssignment
Page 41
Asofthetimeofthiswriting,thelatestservicepackavailableforNTServer4is
version6a.Wemayalsoselectivelyapplytheavailablehotfixes(nowbeingreferred
tobyMicrosoftas“securityupdates”).
FineTuningtheNTConfiguration
StefanNorberginhisarticle“BuildingaWindowsNTbastionhostinpractice”
outlinesseveralmajorstepstoarmorageneralNTinstallation
6
.Someofthesesteps
canbeappliedinourfirewallinstallation,including:
n Removeunusednetworkservices.
n Disableunusedservices.
n DisableNetBIOS.
n Removeunusedandpotentiallydangerouscomponents.
n Encryptthesystemaccountsdatabase.
n Strengthentheaccountandauditsettings.
Notethat:
n IIShasnotbeeninstalledatthefirstplace.ThereisnoneedtohaveIISrunning
onafirewallsystem.
n IPwastheonlyprotocolselectedduringsysteminstallation.
n NTFSistheonlyfilesystemonthecomputer.FATisnotsecure,andisnottobe
consideredatall.
Step1–Removeunusednetworkservices
Inoursystem,thefollowingnetworkservices(whichhavebeeninstalledbydefault)
areremoved:
n Workstation(whichinturnremovesComputerBrowser)
n NetBIOSInterface
6
http://secinf.net/info/nt/ntbastion/
Comentários a estes Manuais