Re: Security Hardening



Hiding the computer from the browse list will do very little to increase
security, as many attacks are done via an IP scan by a program, not by
looking at the browse list (mostly there for human eyes). Also, an
attacker may often not be in a position (for example, in the same
workgroup/subnet) to see the browse list anyway.

=?Utf-8?B?REQ=?= <DD@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
news:638F43A5-77EE-4050-9004-A3B4CFF98CD1@xxxxxxxxxxxxx:

Hi Paul,

What problems you will forsee if we hide the computer ?


"Paul Bergson [MVP-DS]" wrote:

Hiding drives isn't going to do much for you and will only create
problems if you did do it.


To turnoff auto play you can use a gpo (This is what we do)

Machine / Administrative Templates / System / Policy - Turn off
Autoplay = Enabled, Turn off Auto play on = all drives

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no
rights.

"DD" <DD@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:83184562-003E-4CC1-B65A-3711C93CA94E@xxxxxxxxxxxxxxxx
Would like to know

1) how to hide the computer from network browse list -
Prevent a potential attacker inside the firewall from generating a
list of available network resources

2) Disable Autorun- Prevent a malicious program from starting when
media is
inserted

on windows 2003 server and DC





.



Relevant Pages

  • [NT] Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (MS03-044)
    ... Get your security news from a reliable source. ... A security vulnerability exists in the Help and Support Center function ... *Microsoft Windows Millennium Edition ... An attacker could exploit the vulnerability by constructing a URL that, ...
    (Securiteam)
  • [UNIX] Security Analysis of VTun
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... An attacker can modify ... Packet forwarding: ... password) as encryption key. ...
    (Securiteam)
  • [REVS] Security Considerations for Web-based Applications
    ... Get your security news from a reliable source. ... consequences of this ranges from the erosion of customer confidence in the ... of poorly implemented host naming procedures or web-application URL ... The attacker may choose to inject ...
    (Securiteam)
  • [NT] Windows Media Player Directory Traversal Vulnerability (WMZ)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... When Media Player 7 or 8 is installed, ... As most other Internet Explorer vulnerabilities, ... cannot be guessed by a potential attacker. ...
    (Securiteam)
  • [NT] MHTML vulnerability in Outlook Express
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... A vulnerability in Outlook Express allows an attacker to run code of the ... If an attacker were to host a malicious website that contained an MHTML ...
    (Securiteam)