kurt.dillard.c@g2-inc.com kurtdillard@msn.com



Similar documents
Tool Tip. SyAM Management Utilities and Non-Admin Domain Users

Windows 7 / Server 2008 R2 Configuration Overview. By: Robert Huth Dated: March 2014

Using Logon Agent for Transparent User Identification

Compliance series Guide to meeting requirements of USGCB

WINDOWS 7 & HOMEGROUP

MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # )

REMOTE DESKTOP WEB PORTAL (RD Web) ACCESS GUIDE Updated 12/30/2013

Windows Firewall must be enabled on each host to allow Remote Administration. This option is not enabled by default

Administration Guide. . All right reserved. For more information about Specops Gpupdate and other Specops products, visit

Belarc Advisor Security Benchmark Summary

nitrobit group policy

Autograph 3.3 Network Installation

Administration Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

Kepware Technologies Remote OPC DA Quick Start Guide (DCOM)

How To Use A Policy Auditor (Macafee) To Check For Security Issues

ACTIVE DIRECTORY DEPLOYMENT

Setting up DCOM for Windows XP. Research

The SSL device also supports the 64-bit Internet Explorer with new ActiveX loaders for Assessment, Abolishment, and the Access Client.

System Area Management Software Tool Tip: Agent Deployment utilizing. the silent installation with Active Directory

Installing GFI LANguard Network Security Scanner

Centralized Mac Home Directories On Windows Servers: Using Windows To Serve The Mac

Quick Start Guide for VMware and Windows 7

STATISTICA VERSION 12 STATISTICA ENTERPRISE SMALL BUSINESS INSTALLATION INSTRUCTIONS

Federated Identity Service Certificate Download Requirements

XMap 7 Administration Guide. Last updated on 12/13/2009

How to Use Remote Access Using Internet Explorer

Step By Step Guide: Demonstrate DirectAccess in a Test Lab

DC Agent Troubleshooting

Hardening Guide for EventTracker Server

STATISTICA VERSION 9 STATISTICA ENTERPRISE INSTALLATION INSTRUCTIONS FOR USE WITH TERMINAL SERVER

Guide to deploy MyUSBOnly via Windows Logon Script Revision 1.1. Menu

Installing and Configuring WhatsUp Gold

6421B: How to Install and Configure DirectAccess

Paul McFedries. Home Server 2011 LEASHE. Third Edition. 800 East 96th Street, Indianapolis, Indiana USA

Setting Up a Unisphere Management Station for the VNX Series P/N Revision A01 January 5, 2010

TECHNICAL DOCUMENTATION SPECOPS DEPLOY / APP 4.7 DOCUMENTATION

MailStore Outlook Add-in Deployment

ICT Professional Optional Programmes

OneStop Reporting 3.7 Installation Guide. Updated:

CS 356 Lecture 25 and 26 Operating System Security. Spring 2013

1. Introduction to DirectAccess. 2. Technical Introduction. 3. Technical Details within Demo. 4. Summary

Sophos UTM. Remote Access via IPsec Configuring Remote Client

Appendix B Lab Setup Guide

Server Sentinel Client Workstation

Installation Guide. . All right reserved. For more information about Specops Deploy and other Specops products, visit

WatchGuard Mobile User VPN Guide

Qualys PC/SCAP Auditor

TrueEdit Remote Connection Brief

Microsoft Windows Server 2012 R2 Remote Desktop Services - How to Set Up (Mostly) Seamless Logon for RDP Connections

Quick Start Guide for Parallels Virtuozzo

GTS Software Pty Ltd. Remote Desktop Services

LANDesk Patch and Compliance. Common Troubleshooting steps for Vulnerability Remediation.

Installation Instruction STATISTICA Enterprise Server

Installation Instruction STATISTICA Enterprise Small Business

E-Notebook SQL 12.0 Desktop Database Installation Guide. E-Notebook SQL 12.0 Desktop Database Installation Guide

User Management Guide

Kaseya 2. User Guide. Version R8. English

70-685: Enterprise Desktop Support Technician

AWS Directory Service. Simple AD Administration Guide Version 1.0

SECURITY BEST PRACTICES FOR CISCO PERSONAL ASSISTANT (1.4X)

ms-help://ms.technet.2005mar.1033/security/tnoffline/security/smbiz/winxp/fwgrppol...

Contents. VPN Instructions. VPN Instructions... 1

Module 8: Implementing Group Policy

Defense Security Service Industrial Security Field Operations NISP Authorization Office. Technical Assessment Guide for Windows 7 Operating System

NetWrix Password Manager. Quick Start Guide

Windows 7, Enterprise Desktop Support Technician

Citrix Access on SonicWALL SSL VPN

Software Version 5.1 November, Xerox Device Agent User Guide

QUANTIFY INSTALLATION GUIDE

How to - Install EventTracker and Change Audit Agent

Foxit Enterprise Reader GPO User Guide

XIA Configuration Server

Advanced Event Viewer Manual

GFI LANguard 9.0 ReportPack. Manual. By GFI Software Ltd.

Microsoft. Pro: Upgrading to Windows 7 MCITP Enterprise Desktop Support Technician.

1. Installation Overview

SINGLE SIGN-ON FOR MTWEB

E-Notebook SQL 12.0 Desktop Database Migration and Upgrade Guide. E-Notebook SQL 12.0 Desktop Database Migration and Upgrade Guide

Before You Begin, Your Computer Must Meet the System Requirements

ShareFile On-Demand Sync can be installed via EXE or MSI. Both installation types can be downloaded from

Windows Clients and GoPrint Print Queues

Password Manager Windows Desktop Client

Configuration of Microsoft Time Server

Building the SAP Business One Cloud Landscape Part of the SAP Business One Cloud Landscape Workshop

Abila Nonprofit Online. Connection Guide

User Guide Microsoft Exchange Remote Test Instructions

Using TS-ACCESS for Remote Desktop Access

Intelligent Power Protector User manual extension for Microsoft Virtual architectures: Hyper-V 6.0 Manager Hyper-V Server (R1&R2)

Deployment of Keepit for Windows

Changing Your Cameleon Server IP

Management Utilities Configuration for UAC Environments

Hardening IIS Servers

Remote Access Services Microsoft Windows - Installation Guide

Dell UPS Local Node Manager USER'S GUIDE EXTENSION FOR MICROSOFT VIRTUAL ARCHITECTURES Dellups.com

OUTLOOK WEB ACCESS (OWA) AND SSL VPN HOME USERS MANUAL

TestElite - Troubleshooting

System Administration Training Guide. S100 Installation and Site Management

Receiver Updater for Windows 4.0 and 3.x

Web. Security Options Comparison

Transcription:

kurt.dillard.c@g2-inc.com kurtdillard@msn.com

What Changed Since Alpha What Hasn t Changed How do the USGCB and FDCC Relate? Building Your Test Lab Resources

Core Networking - Dynamic Host Configuration Protocol (DHCP-In) Core Networking - Dynamic Host Configuration Protocol (DHCPV6-In) Were: Not configured Now: Enabled: Yes Debug programs user right Was: No one Now: Administrators Take control of any process Debug any process including the kernel Do not give to non-admins

Do not process the legacy Run list Was: Enabled Now: Not defined Blocks execution of applications at HKLM\Software\Microsoft\Windows\CurrentVersion\R un Minor speed-bump for malware Requires admin rights to modify the key Dozens of other ways to launch malware at startup if you have admin rights Impact: Numerous legitimate apps

Require trusted path for credential entry Was: Enabled Now: Not configured User Account Control: Behavior of the elevation prompt for standard users Was: Prompt for credentials Now: Prompt for credentials on the secure desktop MSS: (NtfsDisable8dot3NameCreation) Enable the computer to stop generating 8.3 style filenames Was: Enabled Now: Not configured

Turn off Windows Update device driver search prompt Turn off Windows Update device driver searching Were: Enabled Now: Not configured Turn off Automatic Root Certificates Update Was: Enabled Now: Not configured WLAN AutoConfig system service Was: Disabled Now: Not configured

Systems will hibernate after 20 minutes of inactivity Potentially impacted: Enterprise management Remote Desktop Services (RDS) users Systems that process long running jobs Investigate Wake-on-LAN (WOL) Subnet Directed Broadcasts (SDB)

Still mandatory, however Under specific conditions agencies may adjust those settings. Our SCAP 1.0 content does not support conditional logic, so track these as deviations, SCAP 1.1 content will support conditional logic.

Access this computer from the network User right necessary for establishing IPsec connections Limited to Administrators Internet Key Exchange (IKE) fails Granting the right to Domain Computers or Authenticated Users should resolve it IPv6 transitional technologies 6to4, IP-HTTPS, ISATAP, & Teredo

Windows Error Reporting Remote Assistance Windows NTP Client Remote Desktop Services Windows Updates Bluetooth

What Changed Since Alpha What Hasn t Changed How do the USGCB and FDCC Relate? Building Your Test Lab Resources

Users still cannot have admin privileges Can t download and install ActiveX controls, add-ons, or Desktop Gadgets Download signed ActiveX controls Download unsigned ActiveX controls Initialize and script ActiveX controls not marked as safe No prompts Solutions?

Windows XP, Windows Server 2003 300+ root certs Impacts performance of many tasks Windows Root Certificate Program Default trusted CAs baked into Windows Vista and later have a couple dozen certs Certs can be added and removed dynamically Turn off Automatic Root Certificates Update Disables this feature Lots of files/programs will be treated as unsigned Lots of HTTPS web sites will show invalid cert

You know this dialog box?

Windows uses IE security zones Tracks origin within the NTFS alternate data stream Allows Windows to present suitable messages based on origin Hide mechanisms to remove zone information Hides these messages Makes it difficult to open downloaded files

Stored in profiles, in NTUSR.DAT Dynamically loaded into HKey_Current_User Problems HKCU doesn t exist if nobody is logged on Scanner can t access if someone is logged on User can t log on if NTUSR.DAT is loaded in scanner Solutions Use impersonation to scan logged on user Scan all profiles by creating copies of NTUSR.DAT If any profile is non-compliant consider the system non-compliant

Network access: Allow anonymous SID-Name translation XP, Vista, and Win Stored in an unpublished manner Some advanced audit policies Not supported until OVAL 5.7: Audit Kerberos Authentication Service Audit Other Account Logon Events Audit Credential Validation Audit File System Audit Kerberos Service Ticket Operations Audit Network Policy Server Audit Detailed File Share Audit Registry

What Changed Since Alpha What Hasn t Changed How do the USGCB and FDCC Relate? Building Your Test Lab Resources

The FDCC is the authoritative program The USGCB are the baselines for the FDCC Current Windows 7 & Internet Explorer 8 Near future Red Hat Enterprise Linux 5 (Tier 3 DoD just posted) Further out Apple OS X XP, Vista, & IE8 baselines will be reconciled with USGCB

What Changed Since Alpha What Hasn t Changed How do the USGCB and FDCC Relate? Building Your Test Lab Resources

VHDs have no license key. 30 day evaluation period, then not genuine pop-ups. slmgr /rearm Extends the evaluation for another 30 days. Rearm Windows 7 or Vista three times. slmgr /dlv View the amount of time remaining and rearm count.

1. Install an evaluation copy of the Windows 7: http://technet.microsoft.com/en-us/evalcenter/cc442495.aspx. 2. Install Microsoft's Security Compliance Manager (SCM): http://technet.microsoft.com/en-us/library/cc677002.aspx. You will be prompted to download and install SQL Express, Need an Internet connection Or you can download the SQL Express installer manually. 3. Now install the Local Policy Tool: 1. Open the Start menu, click All Programs, click Microsoft Security Compliance Manager, then click LocalGPO. 2. Double-click LocalGPO.msi.

1. Right-click LocalGPO Command Line, and then click Run as administrator. 2. At the command prompt, type cscript LocalGPO.wsf /Path:<path> and then press ENTER. 3. Repeat step 2 for each GPO backups. 4. Reboot. 5. You can manually verify that settings are applied by running gpedit.msc with administrator privileges.

FDCC includes settings prefixed with MSS: AutoAdminLogon AutoShareWks NoDefaultExempt Etc By default they are not visible in the Security Configuration Editor SCEcli.dll renders the security templates UI Customize %systemroot\inf\sceregvl.inf Reinitialize: Regsvr32 SCEcli.dll

Threats and Countermeasures: Security Settings in Windows Server 2003 and Windows XP: http://go.microsoft.com/fwlink/?linkid=15159 Security Compliance Manager: http://technet.microsoft.com/en-us/library/cc677002.aspx Local Policy Tool MSS: settings Import and export local GPO Windows XP, 2003, Vista, 2008, 7, IE7 & 8, Office 2007 SCM future 2008 R2, SQL 2008, Exchange 2007, Office 2010

What Changed Since Alpha What Hasn t Changed How do the USGCB and FDCC Relate? Building Your Test Lab Resources

usgcb@nist.gov http://usgcb.nist.gov/usgcb.rss http://usgcb.nist.gov http://fdcc.nist.gov http://www.energystar.gov http://www.energystar.gov/index.cfm?c=power_mg t.pr_power_mgt_comm_packages http://www.energystar.gov/index.cfm?c=power_mg t.pr_power_mgt_win_task