Re: hisecweb.inf hardening

From: Jason Wasser (jason_at_bryan.edu)
Date: 06/22/05


Date: Wed, 22 Jun 2005 09:53:39 -0400

James,

You can use the Local Security Policy MMC snap-in to setup the
hisecweb.inf security template. Right-click on the security policy and
click Import. It should take you right to c:\windows\system32\security
which has all the inf security templates. Like the other guys said it's
best to use the other tools first to see what is going to be applied
before you just turn it on. The higher the security you set the more
likely things will start breaking.

James Butler wrote:
> Although, Windows 2003 claim to be secure by default, I don't trust that
> statement, I still see services running that shouldn't.
>
> I am trying to find the best way to harden Win2003 servers, should I use the
> AD to apple hisecweb.inf file to the host, or should I just manually start
> turning off services. How do I secure Stand alone servers such as public web
> server, does inf file exist for it. Since these public servers are not
> member of the forest, how does one apply the inf file.
>
>
> Where can I find info on what hisecweb.inf actually does to a server ?
>



Relevant Pages

  • Re: DMZ NT4 TO Internal 2000 AD One-Way Trust via Firewall
    ... leverage an effectivity security policy to ensure that password complexities ... > currently a mess of local and domain users, no security policy, etc. ... DMZ, not publicly accessible) that aren't going away within the stated ... to non-DC web servers in the DMZ on 80 and 443 - none of which are directed ...
    (microsoft.public.windows.server.active_directory)
  • Re: Need urgent help regarding security
    ... There is plenty of security info out there ... email from even a dozen servers is small. ... an OS version upgrade should not be taken lightly. ... Given that your root password was apparently found on the servers, ...
    (freebsd-questions)
  • [Full-Disclosure] w32.frethem.k@mm and good reading
    ... Script kiddies deface websites. ... only obfuscating your own perception of security. ... >> vulnerabilities in a particular operating system or server software ... >> Imagine a custom operating system used by only a few servers, ...
    (Full-Disclosure)
  • [Full-Disclosure] w32.frethem.k@mm and good reading
    ... Script kiddies deface websites. ... only obfuscating your own perception of security. ... >> vulnerabilities in a particular operating system or server software ... >> Imagine a custom operating system used by only a few servers, ...
    (Full-Disclosure)
  • RE: IIS6 Security and other web servers
    ... IIS6 Security and other web servers ... I know of no Windows architecture that is exposed directly to ... I know of a number of LAMP-type servers that are ... exposed directly to the Internet with no intervening layers. ...
    (Security-Basics)