19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Communications Remarks<br />

____________________________________________________________________ .........................................<br />

If Windows for Workgroups or Windows 95 is installed on the PC, the threats<br />

that can be posed by the use of Peer-to-Peer functions must also be considered<br />

(see chapter 6.3 Peer-to-Peer Network). <strong>The</strong> particular problem of stored<br />

passwords must be emphasised. Passwords are stored in files with the name<br />

[log-on name].pwl. <strong>The</strong>y are stored encrypted but can still be read with<br />

various programmes. It is absolutely necessary that a user logging on to a<br />

Windows NT system from WfW or Windows 95, observes the notes in<br />

safeguard S 4.46 Use of the log-on password under WfW and Windows 95. In<br />

any case, administrators must ensure that a list of passwords is not created.<br />

Additional controls:<br />

- Have shared directories been provided with too many permissions?<br />

- Are network access points sufficiently protected (organisationally or<br />

technically)?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!