Spacer Sidebar Directory Map

The Training Book, the handbook for trainers

The Technical Writer's Checklist

 


ITrain - International Association of Information Technology Trainers

Windows NT Security

Preventing unauthorized entry


ITINFO Sponsor

FastTips Newsletters

Having trouble keeping in touch with your clients? Not touching them at least twice a month?

FastTips newsletters are hard-hitting, to-the-point newsletters filled with useful computer tips & tricks.

Pre-printed with your company's name, address, and phone number, they'll keep your clients coming back for more.

Click for FastTips Newsletters for YOUR clients

Internet Poll
Have you attended a seminar via e-learning?
yes
no

poll archive


Securing a Public Windows NT Station

by Dave Murphy
ISSN 1535-3613

Dave Murphy, DGL President & ITrain founder One of the subjects that's most requested of me is network security, specifically, how do I secure a computer from public tampering.

I did a bit of research, and came up with a few recommendations re securing a Windows NT system that's made available to run Microsoft Internet Explorer, such as might be found in a public kiosk or library.

But first, a warning: Using the Registry Editor incorrectly can cause serious, system- wide problems that may require you to reinstall Windows NT to correct them. Microsoft cannot guarantee that any problems resulting from the use of the Registry Editor can be solved. Use this tool at your own risk.

  1. It is the best that the user works with the guest account. You should not allow password changes for this account. Don't allow local shutdown (User Manager: Policies/User Rights). It is also required that all local drives are formatted in NTFS. Steps 7 and 8 also require the workstations to be member of a domain.

  2. Replace Explorer.exe as a shell with Internet Explorer (HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon : Shell). Be sure to place the full path to Iexplore.exe in this entry. For other applications, place the main executable file or a launcher application here.

  3. Change the permissions for %Systemroot%\System32\Taskmgr.exe so the guest account does not have any privileges for this file (no access). This prevents the user from running Task Manager off the security dialog.

  4. Rename the administrative account and specify a password so users have a hard time hacking it.

  5. Use AutoAdminLogon so only experienced users know how to specify a different name for logon (hold shift while logging off). Even if they manage to get to the logon dialog box, they still have to know about an account.

  6. Disable ShutdownWithoutLogon. It's also located in the Winlogon key mentioned above.

  7. Create a Default System Policy that only allows Iexplore.exe to run and place it on the NETLOGON share of all DCs. It's in Default User Properties, System\Restrictions\Run only allowed Windows applications. Instead of Iexplore.exe, you can also specify the application(s) of your choice. The main executable file or launcher application does not need to be part of this set.

  8. Enable all policy restrictions in Shell\Restrictions so the user only sees the computer and files to be saved end up in the %Systemroot%\Profiles\\desktop directory.

  9. You can also restrict access to %Systemroot%\Profiles\\desktop so the user only can read files from there. This is the only folder the user will be able to see if you checked all items in step 8.

  10. Hide the keyboard and computer behind a locked door; don't announce that it's even there.

Call for Comments

What do you think? How have you kept your systems secure? Leave your comments on the message center.

References

Message Center


Subscribe to ITINFO.
Receive computing and Internet news & tips
by subscribing to the ITINFO information service.
Type your Internet email address in the form, and click "Subscribe."
Email Address:

Damar Group, Ltd. helps business use technology.

ITINFO is again accepting sponsors. Sponsor messages are included in ITINFO's email newsletter and are permanently posted to DGL's website and online reference areas.

ITINFO is an electronic publication of Damar Group, Ltd., publisher of Training Express computer learning guides. Comments and submissions to info@dgl.com.

Previous issues are on our website at http://dgl.com/itinfo/.

updated December 14, 1999
http://dgl.com/itinfo/1999/it991214.html

Return to DGL homepage
Copyright © 1999, Damar Group, Ltd., All Rights Reserved