Testing the baseline dc *inf file/penetration testing

From: James (james_at_icondesigns.us)
Date: 07/31/03


Date: Thu, 31 Jul 2003 07:53:25 -0700


Now that we have basically imported/tweaked the baseline
*inf file mentioned on
http://www.microsoft.com/technet/treeview/default.asp?
url=/technet/security/prodtech/Windows/Win2kHG/05SConfg.asp

is there anyway or best practices in testing the following:

Account Policies
Local Policies
Audit Log Management
Default Group Accounts
Default User Accounts
System Services
Securing the File System
Share Folder Permissions
Securing the Registry
IPSec Policy
Encrypting File System
Enable Automatic Screen Lock Protection
Update the System Emergency Repair Disk

What we need is a best practices procedure in penetration
testing to comprehensively test our security/registry
permissions. I am aware of MBSA, but is this the only tool
available?

Regards,
James



Relevant Pages

  • RE: NDS 6 to Win2K3 File Migration
    ... Let me see if I can clarify this cluttered environment ... ... Netware client to log in and gain access to the Netware File system. ... since we already have the Computer accounts and user accounts in the AD ... we would like to map the Novell account with the existing AD account. ...
    (microsoft.public.windows.server.migration)
  • Re: Where to set the domain password policy up?
    ... The Account Policies located in the Default Domain Controllers Policy ... This would therefore affect the local user accounts in that local SAM. ...
    (microsoft.public.windows.server.active_directory)
  • Re: hide organizational unit from view in active directory
    ... The 2003 version of best practices is here: ... hiding the accounts from the readers). ... I have yet to see a good reason to hide any accounts from ... Author of O'Reilly Active Directory Third Editionwww.joeware.net ...
    (microsoft.public.windows.server.active_directory)
  • Securing Service Accounts - Good Practices
    ... what are the good practices for creating, managing, and securing service ... insecure) and assign domain admin privileges to most of these accounts. ... remove the service accounts from full access privileges, ...
    (Security-Basics)
  • Apple Mac OS X Security Recommendations
    ... including best practices with regard to ... using separate non-administrator Mac OS X user accounts for day-to-day ...
    (comp.sys.mac.system)