22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

► Install the most recent Service Pack and hotfixes appropriate to the platform<br />

and installation. Service Pack 6a is the most often recommended Service<br />

Pack for this platform, along with several additional hotfixes.<br />

► Remove unnecessary services installed automatically during the install<br />

process. These services include the following:<br />

– Remote Procedure Call (RPC)<br />

– NetBIOS<br />

– Computer Browser<br />

Removing these services might impact the functionality of the server. The<br />

software requirements for the intended configuration should be checked, or,<br />

better yet, a lab install should be performed and the configuration tested<br />

before deploying it in a production environment.<br />

These services can be removed by choosing: Control Panel → Network →<br />

Services:<br />

– Workstation: May impact some services such as at. While not as important<br />

as the Server service, it should nonetheless be checked with care;<br />

– Server: Might impact some of the server performance. This should be<br />

checked with the greatest of care and this service removed only if no<br />

negative performance impacts are noted.<br />

► Unbind WINS from TCP/IP. Choose Control Panel → Network → Bindings.<br />

Select “All Protocols” from the drop-down menu. Click WINS Client (TCP/IP)<br />

and then Disable/Remove.<br />

► Use a nonexistent workgroup. There is no reason for a firewall or DMZ server<br />

to participate in domain or workgroup activities.<br />

► Ensure that the following services are disabled:<br />

– Alerter: This is a notification service to deliver messages to users of<br />

certain administrative events.<br />

– ClipBook: This allows clipbook contents to be seen by remote clipbooks.<br />

– DHCP Client: This allows the network settings to be configured by remote<br />

means.<br />

– Messenger: This sends and receives messages sent by administrators or<br />

the alerter service.<br />

– NetBIOS Interface: This provides NetBIOS over TCP/IP.<br />

– Net Logon: This provides pass-through (workstation) or authentication and<br />

domain security database synchronization (server) to other machines in a<br />

domain.<br />

– Network DDE: This provides dynamic data exchange in a networked<br />

environment to remote machines.<br />

Chapter 9. Server hardening 367

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!