19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Safeguard Catalogue - Organisation Remarks<br />

____________________________________________________________________ .........................................<br />

manager. <strong>The</strong> user-account manager cannot set up new users or groups. He<br />

may, however, delete users or groups which have been allocated to him.<br />

A workgroup-manager has all the privileges of a user-account-manager.<br />

Moreover, he can set up new users and groups. An additional task of the<br />

workgroup manager is the setting-up of printing queues.<br />

Use of the NCP-Packet-Signature<br />

Communication between Novell Netware clients and a Novell Netware-server<br />

is controlled by the Netware Core Protocol (NCP). Client and Server exchange<br />

individual packets which contain data. A potential attacker can monitor these<br />

packets by using special programs (see T 5.58 "Hacking Novell Netware") and<br />

can manipulate packets belonging to highly privileged users.<br />

<strong>The</strong> Packet-Signature has been developed to counteract this threat. When a<br />

user logs on to the server, a secret key will be established. If a workstation<br />

then sends an inquiry to the server via NCP, it will be provided with a<br />

signature formed from the secret key and the signature of the previous packet.<br />

This signature will be attached to the relevant packet and sent to the server.<br />

<strong>The</strong> server will verify the packet signature before dealing with the actual<br />

inquiry.<br />

With the option Set NCP Packet Signature -value-, the packet signature can be<br />

activated on the server.<br />

<strong>The</strong> possible levels of NCP-Packet signature are as follows:<br />

Value "0": <strong>The</strong>re are no NCP-Packet-signatures.<br />

Value "1": <strong>The</strong> Novell Netware Server is using NCP-Packet-signatures at the<br />

request of the client.<br />

Value "2": <strong>The</strong> Novell Netware server requires an NCP-Packet-signature<br />

from the client. If the client cannot supply one, communication<br />

between client and server will nonetheless be granted.<br />

Value "3": <strong>The</strong> NCP-Packet-signature is mandatory.<br />

To ensure <strong>IT</strong>-security, the value "3" should be selected for NCP-Packetsignature.<br />

Since installation of the NCP-Packet-signature increases network<br />

demands by 30%, it should be clarified beforehand whether the performance<br />

will be unreasonably reduced.<br />

Restriction of available hard disk memory<br />

With the help of the program SYS:PUBLIC\DSPACE.EXE the available hard<br />

disk memory of a volume or directory should be limited, as experience shows<br />

that use of available hard disk memory increases with the capacity of the hard<br />

disk memory.<br />

Alternatively, once set up, the capacity of each user's personal directory can be<br />

restricted if single directories have been set up for work data.<br />

Blocking programs that are not required<br />

Most of the Novell Netware programs available under SYS:PUBLIC will<br />

generally not be required by Netware users, since many of the functions<br />

(printer configuration, password change, allocation of disks) can be carried out<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!