Solved

NTFS Permissions

Posted on 2004-10-14
6
342 Views
Last Modified: 2013-12-04
Hi

After hearing teh danger of teh admin shares on windows XP and 2000 prof i chnaged my local drives NTFS permmisons from teh defualt to

Admininstrtors (full acsess)
System (full acsess)
authenticated users (readand exccute)

NB i disabled teh guest account too !!

And allows these to filter through to the child ( sub folders) on my machine

My system runs ok so first off are these the safest permmisons to use ?????

Then I went into "Local Security Policy" and imported the "setup security.inf" policy is this the best one again ?????

Thanks
SILKI
0
Comment
Question by:silki
  • 3
  • 3
6 Comments
 
LVL 6

Expert Comment

by:nihlcat
ID: 12309948
Those permissions seem safe.  You might also want to consider renaming your Administrator account, as it is always a target for intruders.
0
 

Author Comment

by:silki
ID: 12317597
Hi,

Thanks for teh feedback so my "Local Security Policy" bein set (imported) back to "setup security.inf" policy is  just like reseting back to default ie teh safest ???

authenticated users have actually got modify perrmisons as im ruuing IIS so i need Inest user to have these permmions but a person woudl need to have an accoutn in hack one of my accounst to get in as authenticated users ???

So you say rename administrators to somehting else ?? woudlnt they need a password though to do any damage ?!?!?

THANKS
SILKI
0
 
LVL 6

Expert Comment

by:nihlcat
ID: 12317646
Of course they would need the password, but they (the bad people) already know the username.  The account 'administrator' is known to all.  Our company's security baseline requires it to be renamed.
0
Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

 

Author Comment

by:silki
ID: 12337035
Thanks nihlcat,

Can you just confirm thsi part for me ...

"so my "Local Security Policy" bein set (imported) back to "setup security.inf" policy is just like reseting back to default" ??? Secure ???
0
 
LVL 6

Accepted Solution

by:
nihlcat earned 125 total points
ID: 12337818
Sorry I totally misread part of your question.  Yes that's the default (setup security.inf).  But no, not very secure at all.  Policies become incrementally more secure.  You may wish to try hisecdc.inf, but it really depends on your network.  You need to be sure to not make it too restrictive.  I think pre-production testing is probably best.

 
More information on predefined security policies:

http://www.microsoft.com/windows2000/en/advanced/help/default.asp?url=/windows2000/en/advanced/help/sag_SCEdefaultpols.htm
0
 

Author Comment

by:silki
ID: 12345611
Thanks ....
0

Featured Post

The Eight Noble Truths of Backup and Recovery

How can IT departments tackle the challenges of a Big Data world? This white paper provides a roadmap to success and helps companies ensure that all their data is safe and secure, no matter if it resides on-premise with physical or virtual machines or in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Users of Windows 10 Professional can disable automatic reboots using the policy editor. This tool is not included in the Windows home edition. But don't worry! Follow the instructions below to install (a Win7) policy editor on your Windows 10 Home e…
Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question