· 9 years ago · Feb 01, 2017, 09:04 PM
1
2 /$$$$$$$$ /$$ /$$
3|__ $$__/| $$ |__/
4 | $$ | $$$$$$$ /$$ /$$$$$$$ /$$$$$$$
5 | $$ | $$__ $$| $$ /$$_____/ /$$_____/
6 | $$ | $$ \ $$| $$| $$ | $$
7 | $$ | $$ | $$| $$| $$ | $$
8 | $$ | $$ | $$| $$| $$$$$$$| $$$$$$$
9 |__/ |__/ |__/|__/ \_______/ \_______/
10
11
12 /$$ /$$ /$$
13| $$ | $$ | $$
14| $$ | $$ /$$$$$$ /$$$$$$$| $$ /$$
15| $$$$$$$$ |____ $$ /$$_____/| $$ /$$/
16| $$__ $$ /$$$$$$$| $$ | $$$$$$/
17| $$ | $$ /$$__ $$| $$ | $$_ $$
18| $$ | $$| $$$$$$$| $$$$$$$| $$ \ $$
19|__/ |__/ \_______/ \_______/|__/ \__/
20
21
22 /$$$$$$ /$$ /$$
23 /$$__ $$ |__/ | $$
24| $$ \__/ /$$ /$$ /$$ /$$$$$$$ /$$$$$$
25| $$ /$$$$| $$ | $$| $$ /$$__ $$ /$$__ $$
26| $$|_ $$| $$ | $$| $$| $$ | $$| $$$$$$$$
27| $$ \ $$| $$ | $$| $$| $$ | $$| $$_____/
28| $$$$$$/| $$$$$$/| $$| $$$$$$$| $$$$$$$
29 \______/ \______/ |__/ \_______/ \_______/
30
31
32Professional Edition
33By Demitri
34
35THIS IS ONLY HAVE OF THE GUIDE. THERE'S WAY MORE IN THE FULL VERSION.
36
37Table of Contents
38
39=Part One=
40=Essential background Knowledge=
41
42[0.0.0] Preface
43[0.0.1] Demitri
44[0.0.2] Disclaimer
45
46[1.0.0] Preface To NetBIOS
47[1.0.1] What is NetBIOS?
48[1.0.2] NetBIOS Names
49[1.0.3] NetBIOS Sessions
50[1.0.4] NetBIOS Datagrams
51[1.0.5] NetBEUI Explained
52[1.0.6] NetBIOS Scopes
53
54[1.2.0] Preface to SMB's
55[1.2.1] What are SMB's?
56[1.2.2] The Redirector
57
58[2.0.0] What is TCP/IP?
59[2.0.1] FTP Explained
60[2.0.2] Remote Login
61[2.0.3] Computer Mail
62[2.0.4] Network File Systems
63[2.0.5] Remote Printing
64[2.0.6] Remote Execution
65[2.0.7] Name Servers
66[2.0.8] Terminal Servers
67[2.0.9] Network-Oriented Window Systems
68[2.1.0] General description of the TCP/IP protocols
69[2.1.1] The TCP Level
70[2.1.2] The IP level
71[2.1.3] The Ethernet level
72[2.1.4] Well-Known Sockets And The Applications Layer
73[2.1.5] Other IP Protocols
74[2.1.6] Domain Name System
75[2.1.7] Routing
76[2.1.8] Subnets and Broadcasting
77[2.1.9] Datagram Fragmentation and Reassembly
78[2.2.0] Ethernet encapsulation: ARP
79
80[3.0.0] Preface to the WindowsNT Registry
81[3.0.1] What is the Registry?
82[3.0.2] In Depth Key Discussion
83[3.0.3] Understanding Hives
84[3.0.4] Default Registry Settings
85
86[4.0.0] Introduction to PPTP
87[4.0.1] PPTP and Virtual Private Networking
88[4.0.2] Standard PPTP Deployment
89[4.0.3] PPTP Clients
90[4.0.4] PPTP Architecture
91[4.0.5] Understanding PPTP Security
92[4.0.6] PPTP and the Registry
93[4.0.7] Special Security Update
94
95[5.0.0] TCP/IP Commands as Tools
96[5.0.1] The Arp Command
97[5.0.2] The Traceroute Command
98[5.0.3] The Netstat Command
99[5.0.4] The Finger Command
100[5.0.5] The Ping Command
101[5.0.6] The Nbtstat Command
102[5.0.7] The IpConfig Command
103[5.0.8] The Telnet Command
104
105[6.0.0] NT Security
106[6.0.1] The Logon Process
107[6.0.2] Security Architecture Components
108[6.0.3] Introduction to Securing an NT Box
109[6.0.4] Physical Security Considerations
110[6.0.5] Backups
111[6.0.6] Networks and Security
112[6.0.7] Restricting the Boot Process
113[6.0.8] Security Steps for an NT Operating System
114[6.0.9] Install Latest Service Pack and applicable hot-fixes
115[6.1.0] Display a Legal Notice Before Log On
116[6.1.1] Rename Administrative Accounts
117[6.1.2] Disable Guest Account
118[6.1.3] Logging Off or Locking the Workstation
119[6.1.4] Allowing Only Logged-On Users to Shut Down the Computer
120[6.1.5] Hiding the Last User Name
121[6.1.6] Restricting Anonymous network access to Registry
122[6.1.7] Restricting Anonymous network access to lookup account names and network shares
123[6.1.8] Enforcing strong user passwords
124[6.1.9] Disabling LanManager Password Hash Support
125[6.2.0] Wiping the System Page File during clean system shutdown
126[6.2.1] Protecting the Registry
127[6.2.2] Secure EventLog Viewing
128[6.2.3] Secure Print Driver Installation
129[6.2.4] The Schedule Service (AT Command)
130[6.2.5] Secure File Sharing
131[6.2.6] Auditing
132[6.2.7] Threat Action
133[6.2.8] Enabling System Auditing
134[6.2.9] Auditing Base Objects
135[6.3.0] Auditing of Privileges
136[6.3.1] Protecting Files and Directories
137[6.3.2] Services and NetBios Access From Internet
138[6.3.3] Alerter and Messenger Services
139[6.3.4] Unbind Unnecessary Services from Your Internet Adapter Cards
140[6.3.5] Enhanced Protection for Security Accounts Manager Database
141[6.3.6] Disable Caching of Logon Credentials during interactive logon.
142[6.3.7] How to secure the %systemroot%\repair\sam._ file
143[6.3.8] TCP/IP Security in NT
144[6.3.9] Well known TCP/UDP Port numbers
145
146[7.0.0] Preface to Microsoft Proxy Server
147[7.0.1] What is Microsoft Proxy Server?
148[7.0.2] Proxy Servers Security Features
149[7.0.3] Beneficial Features of Proxy
150[7.0.4] Hardware and Software Requirements
151[7.0.5] What is the LAT?
152[7.0.6] What is the LAT used for?
153[7.0.7] What changes are made when Proxy Server is installed?
154[7.0.8] Proxy Server Architecture
155[7.0.9] Proxy Server Services: An Introduction
156[7.1.0] Understanding components
157[7.1.1] ISAPI Filter
158[7.1.2] ISAPI Application
159[7.1.3] Proxy Servers Caching Mechanism
160[7.1.4] Windows Sockets
161[7.1.5] Access Control Using Proxy Server
162[7.1.6] Controlling Access by Internet Service
163[7.1.7] Controlling Access by IP, Subnet, or Domain
164[7.1.8] Controlling Access by Port
165[7.1.9] Controlling Access by Packet Type
166[7.2.0] Logging and Event Alerts
167[7.2.1] Encryption Issues
168[7.2.2] Other Benefits of Proxy Server
169[7.2.3] RAS
170[7.2.4] IPX/SPX
171[7.2.5] Firewall Strategies
172[7.2.6] Logical Construction
173[7.2.7] Exploring Firewall Types
174[7.2.3] NT Security Twigs and Ends
175
176=Part Two=
177=Manipulation=
178
179Buy full version to see the rest.
180
181==============Part One==============
182===================Needed Background Knowledge===================
183
184
185[0.0.0] Preface
186
187THIS IS ONLY HALF OF THE OFFICIAL E-BOOK AND IS FOR REVIEW PURPOSES ONLY!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
188
189This book
190covers WindowsNT security issues, Unix, Linux, Irix, Vax, Router configuration, Frontpage,
191Wingate and much much more.
192
193[0.0.1] Demitri
194
195The coolest slavic salesman ever
196
197[0.0.2] Disclaimer
198
199The authors of this
200text do not take responsibility for damages incurred during the practice of any of the information
201contained within this text document.
202
203
204[1.0.0] Preface to NetBIOS
205
206Before you begin reading this section, understand that this section was written for the novice to
207the concept of NetBIOS, but - it also contains information the veteran might find educational. I am
208prefacing this so that I do not get e-mail like "Why did you start your NetBIOS section off so
209basic?" - Simple, its written for people that may be coming from an enviroment that does not use
210NetBIOS, so they would need me to start with basics, thanks.
211
212[1.0.1] Whats is NetBIOS?
213
214NetBIOS (Network Basic Input/Output System) was originally developed by IBM and Sytek as an
215Application Programming Interface (API) for client software to access LAN resources. Since its
216creation, NetBIOS has become the basis for many other networking applications. In its strictest
217sense, NetBIOS is an interface specification for acessing networking services.
218
219NetBIOS, a layer of software developed to link a network operating system with specific
220hardware, was originally designed as THE network controller for IBM's Network LAN. NetBIOS
221has now been extended to allow programs written using the NetBIOS interface to operate on the
222IBM token ring architecture. NetBIOS has since been adopted as an industry standard and now, it
223is common to refer to NetBIOS-compatible LANs.
224
225It offers network applications a set of "hooks" to carry out inter-application communication and
226data transfer. In a basic sense, NetBIOS allows applications to talk to the network. Its intention is
227to isolate application programs from any type of hardware dependancies. It also spares software
228developers the task of developing network error recovery and low level message addressing or
229routing. The use of the NetBIOS interface does alot of this work for them.
230
231NetBIOS standardizes the interface between applications and a LANs operating capabilities. With
232this, it can be specified to which levels of the OSI model the application can write to, making the
233application transportable to other networks. In a NetBIOS LAN enviroment, computers are known
234on the system by a name. Each computer on the network has a permanent name that is
235programmed in various different ways. These names will be discussed in more detail below.
236
237PC's on a NetBIOS LAN communicate either by establishing a session or by using NetBIOS
238datagram or broadcast methods. Sessions allow for a larger message to be sent and handle error
239detection and correction. The communication is on a one-to-one basis. Datagram and broadcast
240methods allow one computer to communicate with several other computers at the same time, but
241are limited in message size. There is no error detection or correction using these datagram or
242broadcast methods. However, datagram communication allows for communication without having
243to establish a session.
244
245All communication in these enviroments are presented to NetBIOS in a format called Network
246Control Blocks (NCB). The allocation of these blocks in memory is dependant on the user
247program. These NCB's are divided into fields, these are reserved for input and output
248respectively.
249
250NetBIOS is a very common protocol used in todays enviroments. NetBIOS is supported on
251Ethernet, TokenRing, and IBM PC Networks. In its original induction, it was defined as only an
252interface between the application and the network adapter. Since then, transport like functions
253have been added to NetBIOS, making it more functional over time.
254
255In NetBIOS, connection (TCP) oriented and connectionless (UDP) communication are both
256supported. It supports both broadcasts and multicasting and supports three distinct services:
257Naming, Session, and Datagram.
258
259[1.0.2] NetBIOS Names
260
261NetBIOS names are used to identify resources on a network. Applications use these names to
262start and end sessions. You can configure a single machine with multiple applications, each of
263which has a unique NetBIOS name. Each PC that supports an application also has a NetBIOS
264station name that is user defined or that NetBIOS derives by internal means.
265
266NetBIOS can consist of up to 16 alphanumeric characters. The combination of characters must
267be unique within the entire source routing network. Before a PC that uses NetBIOS can fully
268function on a network, that PC must register their NetBIOS name.
269
270When a client becomes active, the client advertises their name. A client is considered to be
271registered when it can successfully advertise itself without any other client claiming it has the
272same name. The steps of the registration process is as follows:
273
2741. Upon boot up, the client broadcasts itself and its NetBIOS information anywhere from 6 to 10 to
275ensure every other client on the network receives the information.
276
2772. If another client on the network already has the name, that NetBIOS client issues its own
278broadcast to indicate that the name is in use. The client who is trying to register the already in use
279name, stop all attempts to register that name.
280
2813. If no other client on the network objects to the name registration, the client will finish the
282registration process.
283
284There are two types of names in a NetBIOS enviroment: Unique and Group. A unique name must
285be unique across the network. A group name does not have to be unique and all processes that
286have a given group name belong to the group. Each NetBIOS node maintains a table of all
287names currently owned by that node.
288
289The NetBIOS naming convention allows for 16 characters in a NetBIOS name. Microsoft,
290however, limits these names to 15 characters and uses the 16th character as a NetBIOS suffix. A
291NetBIOS suffix is used by Microsoft Networking software to indentify the functionality installed or
292the registered device or service.
293
294[QuickNote: SMB and NBT (NetBIOS over TCP/IP work very closely together and both use ports
295137, 138, 139. Port 137 is NetBIOS name UDP. Port 138 is NetBIOS datagram UDP. Port 139 is
296NetBIOS session TCP. For further information on NetBIOS, read the paper at the Demitri website
297listed above]
298
299The following is a table of NetBIOS suffixes currently used by Microsoft WindowsNT. These
300suffixes are displayed in hexadecimal format.
301
302Name Number Type Usage
303=========================================================================
304=
305<computername> 00 U Workstation Service
306<computername> 01 U Messenger Service
307<\\_MSBROWSE_> 01 G Master Browser
308<computername> 03 U Messenger Service
309<computername> 06 U RAS Server Service
310<computername> 1F U NetDDE Service
311<computername> 20 U File Server Service
312<computername> 21 U RAS Client Service
313<computername> 22 U Exchange Interchange
314<computername> 23 U Exchange Store
315<computername> 24 U Exchange Directory
316<computername> 30 U Modem Sharing Server Service
317<computername> 31 U Modem Sharing Client Service
318<computername> 43 U SMS Client Remote Control
319<computername> 44 U SMS Admin Remote Control Tool
320<computername> 45 U SMS Client Remote Chat
321<computername> 46 U SMS Client Remote Transfer
322<computername> 4C U DEC Pathworks TCPIP Service
323<computername> 52 U DEC Pathworks TCPIP Service
324<computername> 87 U Exchange MTA
325<computername> 6A U Exchange IMC
326<computername> BE U Network Monitor Agent
327<computername> BF U Network Monitor Apps
328<username> 03 U Messenger Service
329<domain> 00 G Domain Name
330<domain> 1B U Domain Master Browser
331<domain> 1C G Domain Controllers
332<domain> 1D U Master Browser
333<domain> 1E G Browser Service Elections
334<INet~Services> 1C G Internet Information Server
335<IS~Computer_name> 00 U Internet Information Server
336<computername> [2B] U Lotus Notes Server
337IRISMULTICAST [2F] G Lotus Notes
338IRISNAMESERVER [33] G Lotus Notes
339Forte_$ND800ZA [20] U DCA Irmalan Gateway Service
340
341Unique (U): The name may have only one IP address assigned to it. On a network device,
342multiple occurences of a single name may appear to be registered, but the suffix will be unique,
343making the entire name unique.
344
345Group (G): A normal group; the single name may exist with many IP addresses.
346
347Multihomed (M): The name is unique, but due to multiple network interfaces on the same
348computer, this configuration is necessary to permit the registration. Maximum number of
349addresses is 25.
350
351Internet Group (I): This is a special configuration of the group name used to manage WinNT
352domain names.
353
354Domain Name (D): New in NT 4.0
355
356For a quick and dirty look at a servers registered NetBIOS names and services, issue the
357following NBTSTAT command:
358
359nbtstat -A [ipaddress]
360nbtstat –a [host]
361
362[1.0.3] NetBIOS Sessions
363
364The NetBIOS session service provides a connection-oriented, reliable, full-duplex message
365service to a user process. NetBIOS requires one process to be the client and the other to be the
366server. NetBIOS session establishment requires a preordained cooperation between the two
367stations. One application must have issued a Listen command when another application issues a
368Call command. The Listen command references a name in its NetBIOS name table (or WINS
369server), and also the remote name an application must use to qualify as a session partner. If the
370receiver (listener) is not already listening, the Call will be unsuccessful. If the call is successful,
371each application receives notification of session establishment with the session-id. The Send and
372Receive commands the transfer data. At the end of a session, either application can issue a
373Hang-Up command. There is no real flow control for the session service because it is assumed a
374LAN is fast enough to carry the required traffic.
375
376[1.0.4] NetBIOS Datagrams
377
378Datagrams can be sent to a specific name, sent to all members of a group, or broadcast to the
379entire LAN. As with other datagram services, the NetBIOS datagrams are connectionless and
380unreliable. The Send_Datagram command requires the caller to specify the name of the
381destination. If the destination is a group name, then every member of the group receives the
382datagram. The caller of the Receive_Datagram command must specify the local name for which it
383wants to receive datagrams. The Receive_Datagram command also returns the name of the
384sender, in addition to the actual datagram data. If NetBIOS receives a datagram, but there are no
385Receive_Datagram commands pending, then the datagram is discarded.
386
387The Send_Broadcast_Datagram command sends the message to every NetBIOS system on the
388local network. When a broadcast datagram is received by a NetBIOS node, every process that
389has issued a Receive_Broadcast_Datagram command receives the datagram. If none of these
390commands are outstanding when the broadcast datagram is received, the datagram is discarded.
391
392NetBIOS enables an application to establish a session with another device and lets the network
393redirector and transaction protocols pass a request to and from another machine. NetBIOS does
394not actually manipulate the data. The NetBIOS specification defines an interface to the network
395protocol used to reach those services, not the protocol itself. Historically, has been paired with a
396network protocol called NetBEUI (network extended user interface). The association of the
397interface and the protocol has sometimes caused confusion, but the two are different.
398
399Network protocols always provide at least one method for locating and connecting to a particular
400service on a network. This is usually accomplished by converting a node or service name to a
401network address (name resolution). NetBIOS service names must be resolved to an IP address
402before connections can be established with TCP/IP. Most NetBIOS implementations for TCP/IP
403accomplish name address resolution by using either broadcast or LMHOSTS files. In a Microsoft
404enviroment, you would probably also use a NetBIOS Namer Server known as WINS.
405
406[1.0.5] NetBEUI Explained
407
408NetBEUI is an enhanced version of the NetBIOS protocol used by network operating systems. It
409formalizes the transport frame that was never standardized in NetBIOS and adds additional
410functions. The transport layer driver frequently used by Microsofts LAN Manager. NetBEUI
411implements the OSI LLC2 protocol. NetBEUI is the original PC networking protocol and interface
412designed by IBM for the LanManger Server. This protocol was later adopted by Microsoft for their
413networking products. It specifies the way that higher level software sends and receives messages
414over the NetBIOS frame protocol. This protocol runs over the standard 802.2 data-link protocol
415layer.
416
417[1.0.6] NetBIOS Scopes
418
419A NetBIOS Scope ID provides an extended naming service for the NetBIOS over TCP/IP (Known
420as NBT) module. The primary purpose of a NetBIOS scope ID is to isolate NetBIOS traffic on a
421single network to only those nodes with the same NetBIOS scope ID. The NetBIOS scope ID is a
422character string that is appended to the NetBIOS name. The NetBIOS scope ID on two hosts
423must match, or the two hosts will not be able to communicate. The NetBIOS Scope ID also allows
424computers to use the same computer namee as they have different scope IDs. The Scope ID
425becomes a part of the NetBIOS name, making the name unique.
426
427[1.2.0] Preface to SMB’s
428
429The reason I decided to write this section was because recently the Demitri team has been giving
430speeches and lectures. The two questions we most frequently come across is "What is
431NetBIOS?" and "What are SMBs?". Well I hope I have already answered the NetBIOS question
432with the section above. This particular section is being written to better help people understand
433SMB's.
434
435[1.2.1] What are SMB's?
436
437Server Message Blocks are a type of "messaging protocol" that LAN Manager (and NT) clients
438and servers use to communicate with each other. SMB's are a higher level protocol that can be
439transported over NetBEUI, NetBIOS over IPX, and NetBIOS over TCP/IP (or NBT).
440
441SMBs are used by Windows 3.X, Win95, WintNT and OS/2. When it comes to security and the
442compromise of security on an NT network, the one thing to remember about SMBs is that it
443allows for remote access to shared directories, the registry, and other system services, making it
444a deadly protocol in the eyes of security conscience people.
445
446The SMB protocol was originally developed by IBM, and then jointly developed by Microsoft and
447IBM. Network requests that are sent using SMB's are encoded as Network Control Blocks (NCB)
448data structures. The NCB data structures are encoded in SMB format for transmission across the
449network. SMB is used in many Microsoft and IBM networking software:
450
451? MS-Net
452? IBM PC Network
453? IBM LAN Server
454? MS LAN Manager
455? LAN Manager for Unix
456? DEC Pathworks
457? MS Windows for Workgroups
458? Ungermann-Bass Net/1
459? NT Networks through support for LAN Manager
460
461SMB Messages can be categorized into four types:
462
463Session Control: Used to establish or discontinue Redirector connections with a remote network
464resource such as a directory or printer. (The redirector is explained below)
465
466File: Used to access and manipulate file system resources on the remote computer.
467
468Printer: Used by the Redirector to send print data to a remote printer or queue, and to obtain the
469status of remote print devices.
470
471Message: Used by applications and system components to send unicast or broadcast messages.
472
473[1.2.2] The Redirector
474
475The Redirector is the component that enables a client computer to gain access to resources on
476another computer as if the remote resources were local to the client computer. The Redirector
477communicates with other computers using the protocol stack.
478
479The Redirectors primary function is to format remote requests so that they can be understood by
480a remote station (such as a file server) and send them on their way through the network.
481
482The Redirector uses the Server Message Block (SMB) structure as the standard vehicle for
483sending these requests. The SMB is also the vehicle by which stations return responses to
484Redirector requests.
485
486Each SMB contains a header consisting of the command code (which specifies the task that the
487redirector wants the remote station to perform) and several environment and parameter fields
488(which specify how the command should be carried out).
489
490In addition to the header, the last field in the SMB may contain up to 64K of data to be sent to the
491remote station.
492
493[2.0.0] What is TCP/IP?
494
495TCP/IP is a set of protocols developed to allow cooperating computers to share resources across
496a network. It was developed by a community of researchers centered around the ARPAnet
497(Advanced Research Projects Agency). Certainly the ARPAnet is the best-known TCP/IP
498network. However as of June, 87, at least 130 different vendors had products that support
499TCP/IP, and thousands of networks of all kinds use it.
500
501First some basic definitions. The most accurate name for the set of protocols we are describing is
502the "Internet protocol suite". TCP and IP are two of the protocols in this suite. (They will be
503described below.) Because TCP and IP are the best known of the protocols, it has become
504common to use the term TCP/IP to refer to the whole family.
505
506The Internet is a collection of networks, including the Arpanet, NSFnet, regional networks such as
507NYsernet, local networks at a number of University and research institutions, and a number of
508military networks and a growing number of private corporation owned networks. The term
509"Internet" applies to this entire set of networks. The subset of them that is managed by the
510Department of Defense is referred to as the "DDN" (Defense Data Network). This includes some
511research-oriented networks, such as the Arpanet, as well as more strictly military ones. All of
512these networks are connected to each other. Users can send messages from any of them to any
513other, except where there are security or other policy restrictions on access.
514
515Officially speaking, the Internet protocol documents are simply standards adopted by the Internet
516community for its own use. More recently, the Department of Defense issued a MILSPEC
517definition of
518TCP/IP. This was intended to be a more formal definition, appropriate for use in purchasing
519specifications. However most of the TCP/IP community continues to use the Internet standards.
520The MILSPEC version is intended to be consistent with it.
521
522Whatever it is called, TCP/IP is a family of protocols. A few provide "low-level" functions needed
523for many applications. These include IP, TCP, and UDP. (These will be described in a bit more
524detail later.)
525Others are protocols for doing specific tasks, e.g. transferring files between computers, sending
526mail, or finding out who is logged in on another computer. Initially TCP/IP was used mostly
527between
528minicomputers or mainframes. These machines had their own disks, and generally were self-
529contained. Thus the most important "traditional" TCP/IP services are:
530
531[2.0.1] File Transfer
532 The file transfer protocol (FTP) allows a user on any computer
533to get files from another computer, or to send files to another
534computer. Security is handled by requiring the user to specify a user
535name and password for the other computer, or logging into a system that
536allows for Anonymous logins. Provisions are made for
537handling file transfer between machines with different character set,
538end of line conventions, etc. This is not quite the same thing as more
539recent "network file system" or "NetBIOS" protocols, which will be
540described below. Rather, FTP is a utility that you run any time you
541want to access a file on another system. You use it to copy the file
542to your own system. You then work with the local copy. (See RFC 959
543for specifications for FTP.)
544
545[2.0.2] Remote Login
546 The network terminal protocol (TELNET) allows a user to log in
547on any other computer on the network. You start a remote session by
548specifying a computer to connect to. From that time until you finish
549the session, anything you type is sent to the other computer. Note
550that you are really still talking to your own computer. But the telnet
551program effectively makes your computer invisible while it is
552running. Every character you type is sent directly to the other
553system. Generally, the connection to the remote computer behaves much
554like a dialup connection. That is, the remote system will ask you to
555log in and give a password, in whatever manner it would normally ask a
556user who had just dialed it up. When you log off of the other
557computer, the telnet program exits, and you will find yourself talking
558to your own computer. Microcomputer implementations of telnet
559generally include a terminal emulator for some common type of
560terminal. (See RFC's 854 and 855 for specifications for telnet. By the
561way, the telnet protocol should not be confused with Telenet, a vendor
562of commercial network services.)
563
564[2.0.3] Computer Mail
565 This allows you to send messages to users on other
566computers. Originally, people tended to use only one or two specific
567computers. They would maintain "mail files" on those machines. The
568computer mail system is simply a way for you to add a message to
569another user's mail file. There are some problems with this in an
570environment where microcomputers are used. The most serious is that a
571micro is not well suited to receive computer mail. When you send mail,
572the mail software expects to be able to open a connection to the
573addressee's computer, in order to send the mail. If this is a
574microcomputer, it may be turned off, or it may be running an
575application other than the mail system. For this reason, mail is
576normally handled by a larger system, where it is practical to have a
577mail server running all the time. Microcomputer mail software then
578becomes a user interface that retrieves mail from the mail
579server. (See RFC 821 and 822 for specifications for computer mail. See
580RFC 937 for a protocol designed for microcomputers to use in reading
581mail from a mail server.)
582
583These services should be present in any implementation of TCP/IP, except that micro-oriented
584implementations may not support computer mail. These traditional applications still play a very
585important role in TCP/IP-based networks. However more recently, the way in which networks are
586used has been changing. The older model of a number of large, self-sufficient computers is
587beginning to change. Now many installations have several kinds of computers, including
588microcomputers, workstations, minicomputers, and mainframes. These computers are likely to be
589configured to perform specialized
590tasks. Although people are still likely to work with one specific computer, that computer will call on
591other systems on the net for specialized services. This has led to the "server/client" model of
592network services. A server is a system that provides a specific service for the rest of the network.
593A client is another system that uses that service. (Note that the server and client need not be on
594different computers. They could be different programs running on the same computer.)
595
596Here are the kinds of servers typically present in a modern computer setup. Note that these
597computer services can all be provided within the framework of TCP/IP.
598
599[2.0.4] Network File Systems
600 This allows a system to access files on another computer in a
601somewhat more closely integrated fashion than FTP. A network file
602system provides the illusion that disks or other devices from one
603system are directly connected to other systems. There is no need to
604use a special network utility to access a file on another system. Your
605computer simply thinks it has some extra disk drives. These extra
606"virtual" drives refer to the other system's disks. This capability is
607useful for several different purposes. It lets you put large disks on
608a few computers, but still give others access to the disk space. Aside
609from the obvious economic benefits, this allows people working on
610several computers to share common files. It makes system maintenance
611and backup easier, because you don't have to worry about updating and
612backing up copies on lots of different machines. A number of vendors
613now offer high-performance diskless computers. These computers have no
614disk drives at all. They are entirely dependent upon disks attached to
615common "file servers". (See RFC's 1001 and 1002 for a description of
616PC-oriented NetBIOS over TCP. In the workstation and minicomputer
617area, Sun's Network File System is more likely to be used. Protocol
618specifications for it are available from Sun Microsystems.)
619
620[2.0.5] Remote Printing
621 This allows you to access printers on other computers as if
622they were directly attached to yours. (The most commonly used protocol
623is the remote lineprinter protocol from Berkeley Unix. Unfortunately,
624there is no protocol document for this. However the C code is easily
625obtained from Berkeley, so implementations are common.)
626
627[2.0.6] Remote Execution
628 This allows you to request that a particular program be run on
629a different computer. This is useful when you can do most of your work
630on a small computer, but a few tasks require the resources of a larger
631system. There are a number of different kinds of remote execution.
632Some operate on a command by command basis. That is, you request that
633a specific command or set of commands should run on some specific
634computer. (More sophisticated versions will choose a system that
635happens to be free.) However there are also "remote procedure call"
636systems that allow a program to call a subroutine that will run on
637another computer. (There are many protocols of this sort. Berkeley
638Unix contains two servers to execute commands remotely: rsh and
639rexec. The man pages describe the protocols that they use. The
640user-contributed software with Berkeley 4.3 contains a "distributed
641shell" that will distribute tasks among a set of systems, depending
642upon load. Remote procedure call mechanisms have been a topic for
643research for a number of years, so many organizations have
644implementations of such facilities. The most widespread
645commercially-supported remote procedure call protocols seem to be
646Xerox's Courier and Sun's RPC. Protocol documents are available from
647Xerox and Sun. There is a public implementation of Courier over TCP as
648part of the user-contributed software with Berkeley 4.3. An
649implementation of RPC was posted to Usenet by Sun, and also appears as
650part of the user-contributed software with Berkeley 4.3.)
651
652[2.0.7] Name Servers
653 In large installations, there are a number of different
654collections of names that have to be managed. This includes users and
655their passwords, names and network addresses for computers, and
656accounts. It becomes very tedious to keep this data up to date on all
657of the computers. Thus the databases are kept on a small number of
658systems. Other systems access the data over the network. (RFC 822 and
659823 describe the name server protocol used to keep track of host names
660and Internet addresses on the Internet. This is now a required part of
661any TCP/IP implementation. IEN 116 describes an older name server
662protocol that is used by a few terminal servers and other products to
663look up host names. Sun's Yellow Pages system is designed as a general
664mechanism to handle user names, file sharing groups, and other
665databases commonly used by Unix systems. It is widely available
666commercially. Its protocol definition is available from Sun.)
667
668[2.0.8] Terminal Servers
669 Many installations no longer connect terminals directly to
670computers. Instead they connect them to terminal servers. A terminal
671server is simply a small computer that only knows how to run telnet
672(or some other protocol to do remote login). If your terminal is
673connected to one of these, you simply type the name of a computer, and
674you are connected to it. Generally it is possible to have active
675connections to more than one computer at the same time. The terminal
676server will have provisions to switch between connections rapidly, and
677to notify you when output is waiting for another connection. (Terminal
678servers use the telnet protocol, already mentioned. However any real
679terminal server will also have to support name service and a number of
680other protocols.)
681
682[2.0.9] Network-Oriented Window Systems
683 Until recently, high- performance graphics programs had to
684execute on a computer that had a bit-mapped graphics screen directly
685attached to it. Network window systems allow a program to use a
686display on a different computer. Full-scale network window systems
687provide an interface that lets you distribute jobs to the systems that
688are best suited to handle them, but still give you a single
689graphically-based user interface. (The most widely-implemented window
690system is X. A protocol description is available from MIT's Project
691Athena. A reference implementation is publicly available from MIT. A
692number of vendors are also supporting NeWS, a window system defined by
693Sun. Both of these systems are designed to use TCP/IP.)
694
695Note that some of the protocols described above were designed by Berkeley, Sun, or other
696organizations. Thus they are not officially part of the Internet protocol suite. However they are
697implemented
698using TCP/IP, just as normal TCP/IP application protocols are. Since the protocol definitions are
699not considered proprietary, and since commercially-support implementations are widely available,
700it is
701reasonable to think of these protocols as being effectively part of the Internet suite.
702
703Also note that the list above is simply a sample of the sort of services available through TCP/IP.
704However it does contain the majority of the "major" applications. The other commonly-used
705protocols tend to be
706specialized facilities for getting information of various kinds, such as who is logged in, the time of
707day, etc. However if you need a facility that is not listed here, we encourage you to look through
708the current edition of Internet Protocols (currently RFC 1011), which lists all of the available
709protocols, and also to look at some of the major TCP/IP implementations to see what various
710vendors have added.
711
712[2.1.0] General description of the TCP/IP protocols
713
714TCP/IP is a layered set of protocols. In order to understand what this means, it is useful to look at
715an example. A typical situation is sending mail. First, there is a protocol for mail. This defines a
716set of commands which one machine sends to another, e.g. commands to specify who the sender
717of the message is, who it is being sent to, and then the text of the message. However this
718protocol assumes that there is a way to communicate reliably between the two computers. Mail,
719like other application protocols, simply defines a set of commands and messages to be sent. It is
720designed to be used together with TCP and IP.
721
722TCP is responsible for making sure that the commands get through to the other end. It keeps
723track of what is sent, and retransmits anything that did not get through. If any message is too
724large for one
725datagram, e.g. the text of the mail, TCP will split it up into several datagrams, and make sure that
726they all arrive correctly. Since these functions are needed for many applications, they are put
727together into
728a separate protocol, rather than being part of the specifications for sending mail. You can think of
729TCP as forming a library of routines that applications can use when they need reliable network
730communications with another computer.
731
732Similarly, TCP calls on the services of IP. Although the services that TCP supplies are needed by
733many applications, there are still some kinds of applications that don't need them. However there
734are some
735services that every application needs. So these services are put together into IP. As with TCP,
736you can think of IP as a library of routines that TCP calls on, but which is also available to
737applications that don't use TCP. This strategy of building several levels of protocol is called
738"layering". We think of the applications programs such as mail, TCP, and IP, as being separate
739"layers", each of which calls on the services of the layer below it. Generally, TCP/IP applications
740use 4 layers: an application protocol such as mail, a protocol such as TCP that provides services
741need by many applications IP, which provides the basic service of getting datagrams to their
742destination the protocols needed to manage a specific physical medium, such as Ethernet or a
743point to point line.
744
745TCP/IP is based on the "catenet model". (This is described in more detail in IEN 48.) This model
746assumes that there are a large number of independent networks connected together by
747gateways. The user should be able to access computers or other resources on any of these
748networks. Datagrams will often pass through a dozen different networks before getting to their
749final destination.
750
751The routing needed to accomplish this should be completely invisible to the user. As far as the
752user is concerned, all he needs to know in order to access another system is an "Internet
753address". This is an
754address that looks like 128.6.4.194. It is actually a 32-bit number. However it is normally written
755as 4 decimal numbers, each representing 8 bits of the address. (The term "octet" is used by
756Internet documentation for such 8-bit chunks. The term "byte" is not used, because TCP/IP is
757supported by some computers that have byte sizes other than 8 bits.) Generally the structure of
758the address gives
759you some information about how to get to the system. For example, 128.6 is a network number
760assigned by a central authority to Rutgers University. Rutgers uses the next octet to indicate
761which of the
762campus Ethernets is involved. 128.6.4 happens to be an Ethernet used by the Computer Science
763Department. The last octet allows for up to 254 systems on each Ethernet. (It is 254 because 0
764and 255 are not allowed, for reasons that will be discussed later.) Note that 128.6.4.194 and
765128.6.5.194 would be different systems. The structure of an Internet address is described in a bit
766more detail later.
767
768Of course we normally refer to systems by name, rather than by Internet address. When we
769specify a name, the network software looks it up in a database, and comes up with the
770corresponding Internet
771address.
772
773Most of the network software deals strictly in terms of the address. (RFC 882 describes the name
774server technology used to handle this lookup.) TCP/IP is built on "connectionless" technology.
775Information is transferred as a sequence of "datagrams". A datagram is a collection of data that is
776sent as a single
777message. Each of these datagrams is sent through the network individually. There are provisions
778to open connections (i.e. to start a conversation that will continue for some time). However at
779some level, information from those connections is broken up into datagrams, and those
780datagrams are treated by the network as completely separate.
781
782For example, suppose you want to transfer a 15000 octet file. Most networks can't handle a
78315000 octet datagram. So the protocols will break this up into something like 30 500-octet
784datagrams. Each of these datagrams will be sent to the other end. At that point, they will be put
785back together into the 15000-octet
786file. However while those datagrams are in transit, the network doesn't know that there is any
787connection between them. It is perfectly possible that datagram 14 will actually arrive before
788datagram 13. It is also possible that somewhere in the network, an error will occur, and some
789datagram won't get through at all. In that case, that datagram has to be sent again.
790
791Note by the way that the terms "datagram" and "packet" often seem to be nearly interchangable.
792Technically, datagram is the right word to use when describing TCP/IP. A datagram is a unit of
793data, which is what the protocols deal with. A packet is a physical thing, appearing on an Ethernet
794or some wire. In most cases a packet simply contains a datagram, so there is very little
795difference. However they can differ. When TCP/IP is used on top of X.25, the X.25 interface
796breaks the datagrams up into 128-byte packets. This is invisible to IP, because the packets are
797put back together into a single datagram at
798the other end before being processed by TCP/IP. So in this case, one IP datagram would be
799carried by several packets. However with most media, there are efficiency advantages to sending
800one datagram per
801packet, and so the distinction tends to vanish.
802
803[2.1.1] The TCP Level
804
805Two separate protocols are involved in handling TCP/IP datagrams. TCP (the "transmission
806control protocol") is responsible for breaking up the message into datagrams, reassembling them
807at the other end, resending anything that gets lost, and putting things back in the right order. IP
808(the "internet protocol") is responsible for routing individual datagrams. It may seem like TCP is
809doing all the work. And
810in small networks that is true. However in the Internet, simply getting a datagram to its destination
811can be a complex job. A connection may require the datagram to go through several networks at
812Rutgers, a serial line to the John von Neuman Supercomputer Center, a couple of Ethernets
813there, a series of 56Kbaud phone lines to another NSFnet site, and more Ethernets on another
814campus. Keeping track of
815the routes to all of the destinations and handling incompatibilities among different transport media
816turns out to be a complex job.
817
818Note that the interface between TCP and IP is fairly simple. TCP simply hands IP a datagram with
819a destination. IP doesn't know how this datagram relates to any datagram before it or after it. It
820may
821have occurred to you that something is missing here. We have talked about Internet addresses,
822but not about how you keep track of multiple connections to a given system. Clearly it isn't
823enough to get a
824datagram to the right destination. TCP has to know which connection this datagram is part of.
825
826This task is referred to as "demultiplexing." In fact, there are several levels of demultiplexing
827going on in TCP/IP. The information needed to do this demultiplexing is contained in a series of
828"headers". A header is simply a few extra octets tacked onto the beginning of a datagram by
829some protocol in order to keep track of it. It's a lot like putting a letter into an envelope and putting
830an address on the outside of the envelope. Except with modern networks it happens several
831times. It's like you put the letter into a little
832envelope, your secretary puts that into a somewhat bigger envelope, the campus mail center puts
833that envelope into a still bigger one, etc.
834
835Here is an overview of the headers that get stuck on a message that passes through a typical
836TCP/IP network:
837
838We start with a single data stream, say a file you are trying to send to some other computer:
839
840TCP breaks it up into manageable chunks. (In order to do this, TCP has to know how large a
841datagram your network can handle. Actually, the TCP's at each end say how big a datagram they
842can handle, and then they pick the smallest size.)
843
844TCP puts a header at the front of each datagram. This header actually contains at least 20 octets,
845but the most important ones are a source and destination "port number" and a "sequence
846number". The port
847numbers are used to keep track of different conversations. Suppose 3 different people are
848transferring files. Your TCP might allocate port numbers 1000, 1001, and 1002 to these transfers.
849When you are sending a datagram, this becomes the "source" port number, since you are the
850source of the datagram. Of course the TCP at the other end has assigned a port number of its
851own for the conversation. Your TCP has to know the port number used by the other end as well.
852(It finds out when the connection starts, as we will explain below.) It puts this in the "destination"
853port field. Of course if the other end sends a
854datagram back to you, the source and destination port numbers will be reversed, since then it will
855be the source and you will be the destination.
856
857Each datagram has a sequence number. This is used so that the other end can make sure that it
858gets the datagrams in the right order, and that it hasn't missed any. (See the TCP specification for
859details.) TCP doesn't number the datagrams, but the octets. So if there are 500 octets of data in
860each datagram, the first datagram might be numbered 0, the second 500, the next 1000, the next
8611500,
862etc.
863
864Finally, I will mention the Checksum. This is a number that is computed by adding up all the
865octets in the datagram (more or less - see the TCP spec). The result is put in the header. TCP at
866the other end computes the checksum again. If they disagree, then something bad happened to
867the datagram in transmission, and it is thrown away.
868
869The window is used to control how much data can be in transit at any one time. It is not practical
870to wait for each datagram to be acknowledged before sending the next one. That would slow
871things down
872too much. On the other hand, you can't just keep sending, or a fast computer might overrun the
873capacity of a slow one to absorb data. Thus each end indicates how much new data it is currently
874prepared to
875absorb by putting the number of octets in its "Window" field. As the computer receives data, the
876amount of space left in its window decreases. When it goes to zero, the sender has to stop. As
877the receiver processes the data, it increases its window, indicating that it is ready to accept more
878data. Often the same datagram can be used to acknowledge receipt of a set of data and to give
879permission for
880additional new data (by an updated window).
881
882The "Urgent" field allows one end to tell the other to skip ahead in its processing to a particular
883octet. This is often useful for handling asynchronous events, for example when you type a control
884character or other command that interrupts output. The other fields are beyond the scope of this
885document.
886
887[2.1.2] The IP level
888
889TCP sends each of these datagrams to IP. Of course it has to tell IP the Internet address of the
890computer at the other end. Note that this is all IP is concerned about. It doesn't care about what is
891in the
892datagram, or even in the TCP header. IP's job is simply to find a route for the datagram and get it
893to the other end. In order to allow gateways or other intermediate systems to forward the
894datagram, it
895adds its own header.
896
897The main things in this header are the source and destination Internet address (32-bit addresses,
898like 128.6.4.194), the protocol number, and another checksum. The source Internet address is
899simply the address of your machine. (This is necessary so the other end knows where the
900datagram came from.) The destination Internet address is the address of the other machine. (This
901is necessary so any gateways in the middle know where you want the datagram to go.) The
902protocol number tells IP at the other end to send the datagram to TCP. Although most IP traffic
903uses TCP, there are other protocols that can use IP, so you have to tell IP which protocol to send
904the datagram to.
905
906Finally, the checksum allows IP at the other end to verify that the header wasn't damaged in
907transit. Note that TCP and IP have separate checksums. IP needs to be able to verify that the
908header didn't get
909damaged in transit, or it could send a message to the wrong place. For reasons not worth
910discussing here, it is both more efficient and safer to have TCP compute a separate checksum for
911the TCP header and data.
912
913Again, the header contains some additional fields that have not been discussed. Most of them are
914beyond the scope of this document. The flags and fragment offset are used to keep track of the
915pieces when a
916datagram has to be split up. This can happen when datagrams are forwarded through a network
917for which they are too big. (This will be discussed a bit more below.) The time to live is a number
918that is
919decremented whenever the datagram passes through a system. When it goes to zero, the
920datagram is discarded. This is done in case a loop develops in the system somehow. Of course
921this should be impossible, but well-designed networks are built to cope with "impossible"
922conditions.
923
924At this point, it's possible that no more headers are needed. If your computer happens to have a
925direct phone line connecting it to the destination computer, or to a gateway, it may simply send
926the
927datagrams out on the line (though likely a synchronous protocol such as HDLC would be used,
928and it would add at least a few octets at the beginning and end).
929
930[2.1.3] The Ethernet level
931
932Most of our networks these days use Ethernet. So now we have to describe Ethernet's headers.
933Unfortunately, Ethernet has its own addresses. The people who designed Ethernet wanted to
934make sure that no two machines would end up with the same Ethernet address. Furthermore,
935they didn't want the user to have to worry about assigning addresses. So each Ethernet controller
936comes with an address
937builtin from the factory. In order to make sure that they would never have to reuse addresses, the
938Ethernet designers allocated 48 bits for the Ethernet address. People who make Ethernet
939equipment have to
940register with a central authority, to make sure that the numbers they assign don't overlap any
941other manufacturer.
942
943Ethernet is a "broadcast medium". That is, it is in effect like an old party line telephone. When you
944send a packet out on the Ethernet, every machine on the network sees the packet. So something
945is needed
946to make sure that the right machine gets it. As you might guess, this involves the Ethernet
947header. Every Ethernet packet has a 14-octet header that includes the source and destination
948Ethernet address, and
949a type code. Each machine is supposed to pay attention only to packets with its own Ethernet
950address in the destination field. (It's perfectly possible to cheat, which is one reason that Ethernet
951communications are not terribly secure.)
952
953Note that there is no connection between the Ethernet address and the Internet address. Each
954machine has to have a table of what Ethernet address corresponds to what Internet address. (We
955will describe how
956this table is constructed a bit later.) In addition to the addresses, the header contains a type
957code. The type code is to allow for several different protocol families to be used on the same
958network. So you can
959use TCP/IP, DECnet, Xerox NS, etc. at the same time. Each of them will put a different value in
960the type field. Finally, there is a checksum. The Ethernet controller computes a checksum of the
961entire
962packet. When the other end receives the packet, it recomputes the checksum, and throws the
963packet away if the answer disagrees with the original. The checksum is put on the end of the
964packet, not in the
965header.
966
967When these packets are received by the other end, of course all the headers are removed. The
968Ethernet interface removes the Ethernet header and the checksum. It looks at the type code.
969Since the type
970code is the one assigned to IP, the Ethernet device driver passes the datagram up to IP. IP
971removes the IP header. It looks at the IP protocol field. Since the protocol type is TCP, it passes
972the datagram
973up to TCP. TCP now looks at the sequence number. It uses the sequence numbers and other
974information to combine all the datagrams into the original file. The ends our initial summary of
975TCP/IP. There are
976still some crucial concepts we haven't gotten to, so we'll now go back and add details in several
977areas. (For detailed descriptions of the items discussed here see, RFC 793 for TCP, RFC 791 for
978IP, and RFC's
979894 and 826 for sending IP over Ethernet.)
980
981[2.1.4] Well-Known Sockets And The Applications Layer
982
983So far, we have described how a stream of data is broken up into datagrams, sent to another
984computer, and put back together. However something more is needed in order to accomplish
985anything useful. There
986has to be a way for you to open a connection to a specified computer, log into it, tell it what file
987you want, and control the transmission of the file. (If you have a different application in mind, e.g.
988computer mail, some analogous protocol is needed.) This is done by "application protocols".
989
990The application protocols run "on top" of TCP/IP. That is, when they want to send a message,
991they give the message to TCP. TCP makes sure it gets delivered to the other end. Because TCP
992and IP take care of all the networking details, the applications protocols can treat a network
993connection as if it were a simple byte stream, like a terminal or phone line. Before going into
994more details about applications
995programs, we have to describe how you find an application.
996
997Suppose you want to send a file to a computer whose Internet address is 128.6.4.7. To start the
998process, you need more than just the Internet address. You have to connect to the FTP server at
999the other
1000end. In general, network programs are specialized for a specific set of tasks. Most systems have
1001separate programs to handle file transfers, remote terminal logins, mail, etc. When you connect to
1002128.6.4.7, you have to specify that you want to talk to the FTP server. This is done by having
1003"well-known sockets" for each server. Recall that TCP uses port numbers to keep track of
1004individual conversations. User programs normally use more or less random port numbers.
1005However specific port numbers are assigned to the programs that sit waiting for requests.
1006
1007For example, if you want to send a file, you will start a program called "ftp". It will open a
1008connection using some random number, say 1234, for the port number on its end. However it will
1009specify port
1010number 21 for the other end. This is the official port number for the FTP server. Note that there
1011are two different programs involved. You run ftp on your side. This is a program designed to
1012accept commands
1013from your terminal and pass them on to the other end. The program that you talk to on the other
1014machine is the FTP server. It is designed to accept commands from the network connection,
1015rather than an
1016interactive terminal. There is no need for your program to use a well-known socket number for
1017itself. Nobody is trying to find it. However the servers have to have well-known numbers, so that
1018people can open connections to them and start sending them commands. The official port
1019numbers for each program are given in "Assigned Numbers".
1020
1021Note that a connection is actually described by a set of 4 numbers: the Internet address at each
1022end, and the TCP port number at each end. Every datagram has all four of those numbers in it.
1023(The Internet
1024addresses are in the IP header, and the TCP port numbers are in the TCP header.) In order to
1025keep things straight, no two connections can have the same set of numbers. However it is
1026enough for any one number
1027to be different. For example, it is perfectly possible for two different users on a machine to be
1028sending files to the same other machine. This could result in connections with the following
1029parameters:
1030
1031 Internet addresses TCP ports
1032connection 1 128.6.4.194, 128.6.4.7 1234, 21
1033connection 2 128.6.4.194, 128.6.4.7 1235, 21
1034
1035Since the same machines are involved, the Internet addresses are the same. Since they are both
1036doing file transfers, one end of the connection involves the well-known port number for FTP. The
1037only thing
1038that differs is the port number for the program that the users are running. That's enough of a
1039difference. Generally, at least one end of the connection asks the network software to assign it a
1040port number
1041that is guaranteed to be unique. Normally, it's the user's end, since the server has to use a well-
1042known number.
1043
1044Now that we know how to open connections, let's get back to the applications programs. As
1045mentioned earlier, once TCP has opened a connection, we have something that might as well be
1046a simple wire. All
1047the hard parts are handled by TCP and IP. However we still need some agreement as to what we
1048send over this connection. In effect this is simply an agreement on what set of commands the
1049application will
1050understand, and the format in which they are to be sent. Generally, what is sent is a combination
1051of commands and data. They use context to differentiate.
1052
1053For example, the mail protocol works like this: Your mail program opens a connection to the mail
1054server at the other end. Your program gives it your machine's name, the sender of the message,
1055and the
1056recipients you want it sent to. It then sends a command saying that it is starting the message. At
1057that point, the other end stops treating what it sees as commands, and starts accepting the
1058message. Your end then starts sending the text of the message. At the end of the message, a
1059special mark is sent (a dot in the first column). After that, both ends understand that your program
1060is again sending commands. This is the simplest way to do things, and the one that most
1061applications use.
1062
1063File transfer is somewhat more complex. The file transfer protocol involves two different
1064connections. It starts out just like mail. The user's program sends commands like "log me in as
1065this user", "here is
1066my password", "send me the file with this name". However once the command to send data is
1067sent, a second connection is opened for the data itself. It would certainly be possible to send the
1068data on the
1069same connection, as mail does. However file transfers often take a long time. The designers of
1070the file transfer protocol wanted to allow the user to continue issuing commands while the transfer
1071is going
1072on. For example, the user might make an inquiry, or he might abort the transfer. Thus the
1073designers felt it was best to use a separate connection for the data and leave the original
1074command connection for
1075commands. (It is also possible to open command connections to two different computers, and tell
1076them to send a file from one to the other. In that case, the data couldn't go over the command
1077connection.)
1078
1079Remote terminal connections use another mechanism still. For remote logins, there is just one
1080connection. It normally sends data. When it is necessary to send a command (e.g. to set the
1081terminal type or to change some mode), a special character is used to indicate that the next
1082character is a command. If the user happens to type that special character as data, two of them
1083are sent.
1084
1085We are not going to describe the application protocols in detail in this document. It's better to read
1086the RFC's yourself. However there are a couple of common conventions used by applications that
1087will be
1088described here. First, the common network representation: TCP/IP is intended to be usable on
1089any computer. Unfortunately, not all computers agree on how data is represented. There are
1090differences in
1091character codes (ASCII vs. EBCDIC), in end of line conventions (carriage return, line feed, or a
1092representation using counts), and in whether terminals expect characters to be sent individually
1093or a line
1094at a time. In order to allow computers of different kinds to communicate, each applications
1095protocol defines a standard representation.
1096
1097Note that TCP and IP do not care about the representation. TCP simply sends octets. However
1098the programs at both ends have to agree on how the octets are to be interpreted. The RFC for
1099each application specifies the standard representation for that application. Normally it is "net
1100ASCII". This uses ASCII characters, with end of line denoted by a carriage return followed by a
1101line feed. For remote
1102login, there is also a definition of a "standard terminal", which turns out to be a half-duplex
1103terminal with echoing happening on the local machine. Most applications also make provisions for
1104the two
1105computers to agree on other representations that they may find more convenient. For example,
1106PDP-10's have 36-bit words. There is a way that two PDP-10's can agree to send a 36-bit binary
1107file. Similarly,
1108two systems that prefer full-duplex terminal conversations can agree on that. However each
1109application has a standard representation, which every machine must support.
1110
1111Keep in mind that it has become common practice for some corporations to change a services
1112port number on the server side. If your client software is not configured with the same port
1113number, connection will not be successful. We will discuss later in this text how you can perform
1114port scanning on an entire IP address to see which ports are active.
1115
1116[2.1.5] Other IP Protocols
1117Protocols other than TCP: UDP and ICMP
1118
1119So far, we have described only connections that use TCP. Recall that TCP is responsible for
1120breaking up messages into datagrams, and reassembling them properly. However in many
1121applications, we have
1122messages that will always fit in a single datagram. An example is name lookup. When a user
1123attempts to make a connection to another system, he will generally specify the system by name,
1124rather than Internet
1125address. His system has to translate that name to an address before it can do anything.
1126Generally, only a few systems have the database used to translate names to addresses. So the
1127user's system will want to send a query to one of the systems that has the database. This query
1128is going to be very short. It will certainly fit in one datagram. So will the answer. Thus it seems
1129silly to use TCP. Of course TCP does
1130more than just break things up into datagrams. It also makes sure that the data arrives, resending
1131datagrams where necessary. But for a question that fits in a single datagram, we don't need all
1132the
1133complexity of TCP to do this. If we don't get an answer after a few seconds, we can just ask
1134again. For applications like this, there are alternatives to TCP.
1135
1136The most common alternative is UDP ("user datagram protocol"). UDP is designed for
1137applications where you don't need to put sequences of datagrams together. It fits into the system
1138much like TCP. There is a
1139UDP header. The network software puts the UDP header on the front of your data, just as it
1140would put a TCP header on the front of your data. Then UDP sends the data to IP, which adds
1141the IP header, putting
1142UDP's protocol number in the protocol field instead of TCP's protocol number. However UDP
1143doesn't do as much as TCP does. It doesn't split data into multiple datagrams. It doesn't keep
1144track of what it has
1145sent so it can resend if necessary. About all that UDP provides is port numbers, so that several
1146programs can use UDP at once. UDP port numbers are used just like TCP port numbers. There
1147are well-known port
1148numbers for servers that use UDP. Note that the UDP header is shorter than a TCP header. It still
1149has source and destination port numbers, and a checksum, but that's about it. No sequence
1150number, since it is not needed. UDP is used by the protocols that handle name lookups (see IEN
1151116, RFC 882, and RFC 883), and a number of similar protocols.
1152
1153Another alternative protocol is ICMP ("Internet Control Message Protocol"). ICMP is used for error
1154messages, and other messages intended for the TCP/IP software itself, rather than any particular
1155user program. For example, if you attempt to connect to a host, your system may get back an
1156ICMP message saying "host unreachable". ICMP can also be used to find out some information
1157about the network. See RFC 792 for details of ICMP. ICMP is similar to UDP, in that it handles
1158messages that fit in one datagram. However it is even simpler than UDP. It doesn't even have
1159port numbers in its header. Since all ICMP messages are interpreted by the network software
1160itself, no port numbers are needed to say where a ICMP message is supposed to go.
1161
1162[2.1.6] Domain Name System
1163Keeping track of names and information: the domain system
1164
1165As we indicated earlier, the network software generally needs a 32-bit Internet address in order to
1166open a connection or send a datagram. However users prefer to deal with computer names rather
1167than
1168numbers. Thus there is a database that allows the software to look up a name and find the
1169corresponding number. When the Internet was small, this was easy. Each system would have a
1170file that listed all of the
1171other systems, giving both their name and number. There are now too many computers for this
1172approach to be practical. Thus these files have been replaced by a set of name servers that keep
1173track of host
1174names and the corresponding Internet addresses. (In fact these servers are somewhat more
1175general than that. This is just one kind of information stored in the domain system.)
1176
1177Note that a set of interlocking servers are used, rather than a single central one. There are now
1178so many different institutions connected to the Internet that it would be impractical for them to
1179notify a central
1180authority whenever they installed or moved a computer. Thus naming authority is delegated to
1181individual institutions. The name servers form a tree, corresponding to institutional structure. The
1182names
1183themselves follow a similar structure.
1184
1185A typical example is the name BORAX.LCS.MIT.EDU. This is a computer at the Laboratory for
1186Computer Science (LCS) at MIT. In order to find its Internet address, you might potentially have
1187to consult 4
1188different servers. First, you would ask a central server (called the root) where the EDU server is.
1189EDU is a server that keeps track of educational institutions. The root server would give you the
1190names and
1191Internet addresses of several servers for EDU. (There are several servers at each level, to allow
1192for the possibly that one might be down.) You would then ask EDU where the server for MIT is.
1193Again, it
1194would give you names and Internet addresses of several servers for MIT. Generally, not all of
1195those servers would be at MIT, to allow for the possibility of a general power failure at MIT. Then
1196you would ask
1197MIT where the server for LCS is, and finally you would ask one of the LCS servers about BORAX.
1198The final result would be the Internet address for BORAX.LCS.MIT.EDU. Each of these levels is
1199referred to as
1200a "domain". The entire name, BORAX.LCS.MIT.EDU, is called a "domain name". (So are the
1201names of the higher-level domains, such as LCS.MIT.EDU, MIT.EDU, and EDU.)
1202
1203Fortunately, you don't really have to go through all of this most of the time. First of all, the root
1204name servers also happen to be the name servers for the top-level domains such as EDU. Thus
1205a single
1206query to a root server will get you to MIT. Second, software generally remembers answers that it
1207got before. So once we look up a name at LCS.MIT.EDU, our software remembers where to find
1208servers for
1209LCS.MIT.EDU, MIT.EDU, and EDU. It also remembers the translation of BORAX.LCS.MIT.EDU.
1210Each of these pieces of information has a "time to live" associated with it. Typically this is a few
1211days. After that,
1212the information expires and has to be looked up again. This allows institutions to change things.
1213
1214The domain system is not limited to finding out Internet addresses. Each domain name is a node
1215in a database. The node can have records that define a number of different properties. Examples
1216are
1217Internet address, computer type, and a list of services provided by a computer. A program can
1218ask for a specific piece of information, or all information about a given name. It is possible for a
1219node in the
1220database to be marked as an "alias" (or nickname) for another node. It is also possible to use the
1221domain system to store information about users, mailing lists, or other objects.
1222
1223There is an Internet standard defining the operation of these databases, as well as the protocols
1224used to make queries of them. Every network utility has to be able to make such queries, since
1225this is now the official way to evaluate host names. Generally utilities will talk to a server on their
1226own system. This server will take care of contacting the other servers for them. This keeps down
1227the amount of code that has to be in each application program.
1228
1229The domain system is particularly important for handling computer mail. There are entry types to
1230define what computer handles mail for a given name, to specify where an individual is to receive
1231mail, and to
1232define mailing lists. (See RFC's 882, 883, and 973 for specifications of the domain system. RFC
1233974 defines the use of the domain system in sending mail.)
1234
1235[2.1.7] Routing
1236
1237The description above indicated that the IP implementation is responsible for getting datagrams
1238to the destination indicated by the destination address, but little was said about how this would be
1239done. The task of finding how to get a datagram to its destination is referred to as "routing". In
1240fact many of the details depend upon the particular implementation. However some general
1241things can be said.
1242
1243First, it is necessary to understand the model on which IP is based. IP assumes that a system is
1244attached to some local network. We assume that the system can send datagrams to any other
1245system on its own network. (In the case of Ethernet, it simply finds the Ethernet address of the
1246destination system, and puts the datagram out on the Ethernet.) The problem comes when a
1247system is asked to send a datagram to a system on a different network. This problem is handled
1248by gateways. A gateway is a system that connects a network with one or more other networks.
1249Gateways are often normal computers that happen to have more than one network interface. For
1250example, we have a Unix machine that has two different Ethernet interfaces. Thus it is connected
1251to networks 128.6.4 and 128.6.3. This machine can act as a gateway between those two
1252networks. The software on that machine must be set up so that it will forward datagrams from one
1253network to the other. That is, if a machine on network 128.6.4 sends a datagram to the gateway,
1254and the datagram is addressed to a machine on network
1255128.6.3, the gateway will forward the datagram to the destination. Major communications centers
1256often have gateways that connect a number of different networks. (In many cases, special-
1257purpose gateway systems provide better performance or reliability than general-purpose systems
1258acting as gateways. A number of vendors sell such systems.)
1259
1260Routing in IP is based entirely upon the network number of the destination address. Each
1261computer has a table of network numbers. For each network number, a gateway is listed. This is
1262the gateway to be
1263used to get to that network. Note that the gateway doesn't have to connect directly to the network.
1264It just has to be the best place to go to get there. For example at Rutgers, our interface to NSFnet
1265is at
1266the John von Neuman Supercomputer Center (JvNC). Our connection to JvNC is via a high-
1267speed serial line connected to a gateway whose address is 128.6.3.12. Systems on net 128.6.3
1268will list 128.6.3.12 as
1269the gateway for many off-campus networks. However systems on net 128.6.4 will list 128.6.4.1 as
1270the gateway to those same off-campus networks. 128.6.4.1 is the gateway between networks
1271128.6.4 and
1272128.6.3, so it is the first step in getting to JvNC.
1273
1274When a computer wants to send a datagram, it first checks to see if the destination address is on
1275the system's own local network. If so, the datagram can be sent directly. Otherwise, the system
1276expects to
1277find an entry for the network that the destination address is on. The datagram is sent to the
1278gateway listed in that entry. This table can get quite big. For example, the Internet now includes
1279several hundred
1280individual networks. Thus various strategies have been developed to reduce the size of the
1281routing table. One strategy is to depend upon "default routes". Often, there is only one gateway
1282out of a network. This gateway might connect a local Ethernet to a campus-wide backbone
1283network. In that case, we don't need to have a separate entry for every network in the world. We
1284simply define that gateway as a "default". When no specific route is found for a datagram, the
1285datagram is sent to the default gateway. A default gateway can even be used when there are
1286several gateways on a network. There are provisions for gateways to send a message saying "I'm
1287not the best gateway -- use this one instead." (The message is sent via ICMP. See RFC 792.)
1288Most network software is designed to use these messages to add entries to their routing tables.
1289Suppose network 128.6.4 has two gateways, 128.6.4.59 and 128.6.4.1. 128.6.4.59 leads to
1290several other internal Rutgers networks. 128.6.4.1 leads indirectly to the NSFnet. Suppose we set
1291128.6.4.59 as a default gateway, and have no other routing table entries. Now what happens
1292when we need to send a datagram to MIT? MIT is network 18. Since we have no entry for
1293network 18, the datagram will be sent to the default, 128.6.4.59. As it happens, this gateway is
1294the wrong one. So it will forward the
1295datagram to 128.6.4.1. But it will also send back an error saying in effect: "to get to network 18,
1296use 128.6.4.1". Our software will then add an entry to the routing table. Any future datagrams to
1297MIT will then go directly to 128.6.4.1. (The error message is sent using the ICMP protocol. The
1298message type is called "ICMP redirect.")
1299
1300Most IP experts recommend that individual computers should not try to keep track of the entire
1301network. Instead, they should start with default gateways, and let the gateways tell them the
1302routes, as just
1303described. However this doesn't say how the gateways should find out about the routes. The
1304gateways can't depend upon this strategy. They have to have fairly complete routing tables. For
1305this, some sort of
1306routing protocol is needed. A routing protocol is simply a technique for the gateways to find each
1307other, and keep up to date about the best way to get to every network. RFC 1009 contains a
1308review of
1309gateway design and routing. However rip.doc is probably a better introduction to the subject. It
1310contains some tutorial material, and a detailed description of the most commonly-used routing
1311protocol.
1312
1313[2.1.8] Subnets and Broadcasting
1314Details about Internet Addresses: Subnets and Broadcasting
1315
1316As indicated earlier, Internet addresses are 32-bit numbers, normally written as 4 octets (in
1317decimal), e.g. 128.6.4.7. There are actually 3 different types of address. The problem is that the
1318address has to
1319indicate both the network and the host within the network. It was felt that eventually there would
1320be lots of networks. Many of them would be small, but probably 24 bits would be needed to
1321represent all the IP
1322networks. It was also felt that some very big networks might need 24 bits to represent all of their
1323hosts. This would seem to lead to 48 bit addresses. But the designers really wanted to use 32 bit
1324addresses. So they adopted a kludge.
1325
1326The assumption is that most of the networks will be small. So they set up three different ranges of
1327address. Addresses beginning with 1 to 126 use only the first octet for the network number. The
1328other three octets are available for the host number. Thus 24 bits are available for hosts. These
1329numbers are used for large networks. But there can only be 126 of these very big networks. The
1330Arpanet is one, and there are a few large commercial networks. But few normal organizations get
1331one of these "class A" addresses. For normal large organizations, "class B" addresses are used.
1332Class B addresses use the first two octets for the network number. Thus network numbers are
1333128.1 through 191.254. (We avoid 0 and 255, for reasons that we see below. We also avoid
1334addresses beginning with 127, because that is used by some systems for special purposes.) The
1335last two octets are available for host addesses, giving 16 bits of host address. This allows for
133664516 computers, which should be enough for most organizations. (It is possible to get more than
1337one class B address, if you run out.) Finally, class C addresses use three octets, in the range
1338192.1.1 to 223.254.254. These allow only 254 hosts on each network, but there can
1339be lots of these networks. Addresses above 223 are reserved for future use, as class D and E
1340(which are currently not defined).
1341
1342Many large organizations find it convenient to divide their network number into "subnets". For
1343example, Rutgers has been assigned a class B address, 128.6. We find it convenient to use the
1344third octet of the
1345address to indicate which Ethernet a host is on. This division has no significance outside of
1346Rutgers. A computer at another institution would treat all datagrams addressed to 128.6 the same
1347way. They would
1348not look at the third octet of the address. Thus computers outside Rutgers would not have
1349different routes for 128.6.4 or 128.6.5. But inside Rutgers, we treat 128.6.4 and 128.6.5 as
1350separate networks. In
1351effect, gateways inside Rutgers have separate entries for each Rutgers subnet, whereas
1352gateways outside Rutgers just have one entry for 128.6.
1353
1354Note that we could do exactly the same thing by using a separate class C address for each
1355Ethernet. As far as Rutgers is concerned, it would be just as convenient for us to have a number
1356of class C
1357addresses. However using class C addresses would make things inconvenient for the rest of the
1358world. Every institution that wanted to talk to us would have to have a separate entry for each one
1359of our
1360networks. If every institution did this, there would be far too many networks for any reasonable
1361gateway to keep track of. By subdividing a class B network, we hide our internal structure from
1362everyone else,
1363and save them trouble. This subnet strategy requires special provisions in the network software. It
1364is described in RFC 950.
1365
13660 and 255 have special meanings. 0 is reserved for machines that don't know their address. In
1367certain circumstances it is possible for a machine not to know the number of the network it is on,
1368or even its
1369own host address. For example, 0.0.0.23 would be a machine that knew it was host number 23,
1370but didn't know on what network.
1371
1372255 is used for "broadcast". A broadcast is a message that you want every system on the
1373network to see. Broadcasts are used in some situations where you don't know who to talk to. For
1374example, suppose
1375you need to look up a host name and get its Internet address. Sometimes you don't know the
1376address of the nearest name server. In that case, you might send the request as a broadcast.
1377There are also cases where a number of systems are interested in information. It is then less
1378expensive to send a single broadcast than to send datagrams individually to each host that is
1379interested in the information. In order to send a broadcast, you use an address that is made by
1380using your network address, with all ones in the part of the address where the host number goes.
1381For example, if you are on network 128.6.4, you would use 128.6.4.255 for broadcasts. How this
1382is actually implemented depends upon the medium. It is not possible to send broadcasts on the
1383Arpanet, or on point to point lines. However it is possible on an Ethernet. If you use an Ethernet
1384address with all its bits on (all ones), every machine on the Ethernet is supposed to look at that
1385datagram.
1386
1387Although the official broadcast address for network 128.6.4 is now 128.6.4.255, there are some
1388other addresses that may be treated as broadcasts by certain implementations. For convenience,
1389the standard
1390also allows 255.255.255.255 to be used. This refers to all hosts on the local network. It is often
1391simpler to use 255.255.255.255 instead of finding out the network number for the local network
1392and forming a
1393broadcast address such as 128.6.4.255. In addition, certain older implementations may use 0
1394instead of 255 to form the broadcast address. Such implementations would use 128.6.4.0 instead
1395of 128.6.4.255 as the broadcast address on network 128.6.4. Finally, certain older
1396implementations may not understand about subnets. Thus they consider the network number to
1397be 128.6. In that case, they will assume a broadcast address of 128.6.255.255 or 128.6.0.0. Until
1398support for broadcasts is implemented properly, it can be a somewhat dangerous feature to use.
1399
1400Because 0 and 255 are used for unknown and broadcast addresses, normal hosts should never
1401be given addresses containing 0 or 255. Addresses should never begin with 0, 127, or any
1402number above 223. Addresses violating these rules are sometimes referred to as "Martians",
1403because of rumors that the Central University of Mars is using network 225.
1404
1405[2.1.9] Datagram Fragmentation and Reassembly
1406
1407TCP/IP is designed for use with many different kinds of network. Unfortunately, network
1408designers do not agree about how big packets can be. Ethernet packets can be 1500 octets long.
1409Arpanet packets have a maximum of around 1000 octets. Some very fast networks have much
1410larger packet sizes. At first, you might think that IP should simply settle on the smallest possible
1411size. Unfortunately, this would cause serious performance problems. When transferring large
1412files, big packets are far more efficient than small ones. So we want to be able to use the largest
1413packet size possible. But we also want to be able to handle networks with small limits.
1414
1415There are two provisions for this. First, TCP has the ability to "negotiate" about datagram size.
1416When a TCP connection first opens, both ends can send the maximum datagram size they can
1417handle. The
1418smaller of these numbers is used for the rest of the connection. This allows two implementations
1419that can handle big datagrams to use them, but also lets them talk to implementations that can't
1420handle them. However this doesn't completely solve the problem. The most serious problem is
1421that the two ends don't necessarily know about all of the steps in between. For example, when
1422sending data between Rutgers and Berkeley, it is likely that both computers will be on Ethernets.
1423Thus they will both be prepared to handle 1500-octet datagrams. However the connection will at
1424some point end up going over the Arpanet. It can't handle packets of that size. For this reason,
1425there are provisions to split datagrams up into pieces. (This is referred to as "fragmentation".) The
1426IP header contains fields indicating the datagram has been split, and enough information to let
1427the pieces be put back together. If a gateway connects an Ethernet
1428to the Arpanet, it must be prepared to take 1500-octet Ethernet packets and split them into pieces
1429that will fit on the Arpanet. Furthermore, every host implementation of TCP/IP must be prepared
1430to accept pieces and put them back together. This is referred to as "reassembly".
1431
1432TCP/IP implementations differ in the approach they take to deciding on datagram size. It is fairly
1433common for implementations to use 576-byte datagrams whenever they can't verify that the
1434entire path is able to
1435handle larger packets. This rather conservative strategy is used because of the number of
1436implementations with bugs in the code to reassemble fragments. Implementors often try to avoid
1437ever having fragmentation occur. Different implementors take different approaches to deciding
1438when it is safe to use large datagrams. Some use them only for the local network. Others will use
1439them for any network on the same campus. 576 bytes is a "safe" size, which every
1440implementation must support.
1441
1442[2.2.0] Ethernet encapsulation: ARP
1443
1444There was a brief discussion earlier about what IP datagrams look like on an Ethernet. The
1445discussion showed the Ethernet header and checksum. However it left one hole: It didn't say how
1446to figure out
1447what Ethernet address to use when you want to talk to a given Internet address. In fact, there is a
1448separate protocol for this, called ARP ("address resolution protocol"). (Note by the way that ARP
1449is not an IP protocol. That is, the ARP datagrams do not have IP headers.)
1450
1451Suppose you are on system 128.6.4.194 and you want to connect to system 128.6.4.7. Your
1452system will first verify that 128.6.4.7 is on the same network, so it can talk directly via Ethernet.
1453Then it will look up 128.6.4.7 in its ARP table, to see if it already knows the Ethernet address. If
1454so, it will stick on an Ethernet header, and send the packet. But suppose this system is not in the
1455ARP table. There is
1456no way to send the packet, because you need the Ethernet address. So it uses the ARP protocol
1457to send an ARP request. Essentially an ARP request says "I need the Ethernet address for
1458128.6.4.7". Every system listens to ARP requests. When a system sees an ARP request for itself,
1459it is required to respond. So 128.6.4.7 will see the request, and will respond with an ARP reply
1460saying in effect "128.6.4.7 is
14618:0:20:1:56:34". (Recall that Ethernet addresses are 48 bits. This is 6 octets. Ethernet addresses
1462are conventionally shown in hex, using the punctuation shown.) Your system will save this
1463information in its
1464ARP table, so future packets will go directly. Most systems treat the ARP table as a cache, and
1465clear entries in it if they have not been used in a certain period of time.
1466
1467Note by the way that ARP requests must be sent as "broadcasts". There is no way that an ARP
1468request can be sent directly to the right system. After all, the whole reason for sending an ARP
1469request is that
1470you don't know the Ethernet address. So an Ethernet address of all ones is used, i.e. ff:ff:ff:ff:ff:ff.
1471By convention, every machine on the Ethernet is required to pay attention to packets with this as
1472an
1473address. So every system sees every ARP requests. They all look to see whether the request is
1474for their own address. If so, they respond. If not, they could just ignore it. (Some hosts will use
1475ARP requests to
1476update their knowledge about other hosts on the network, even if the request isn't for them.) Note
1477that packets whose IP address indicates broadcast (e.g. 255.255.255.255 or 128.6.4.255) are
1478also sent with an Ethernet address that is all ones.
1479
1480[3.0.0] Preface to the WindowsNT Registry
1481
1482This section is not meant for NT engineers that already know the registry, and its not meant for
1483people that have read the 800+ page books on the registry I’ve seen. This section is meant as a
1484quick guide to get people understanding exactly what this registry thing is.
1485
1486[3.0.1] What is the Registry?
1487
1488The windows registry provides for a somewhat secure, unified database that stores configuration
1489information into a hierarchical model. Until recently, configuration files such as WIN.INI, were the
1490only way to configure windows applications and operating system functions. In todays NT 4
1491environment, the registry replaces these .INI files. Each key in the registry is similar to bracketed
1492headings in an .INI file.
1493
1494One of the main disadvantages to the older .INI files is that those files are flat text files, which are
1495unable to support nested headings or contain data other than pure text. Registry keys can contain
1496nested headings in the form of subkeys. These subkeys provide finer details and a greater range
1497to the possible configuration information for a particular operating system. Registry values can
1498also consist of executable code, as well as provide individual preferences for multiple users of the
1499same computer. The ability to store executable code within the Registry extends its usage to
1500operating system system and application developers. The ability to store user-specific profile
1501information allows one to tailor the environment for specific individual users.
1502
1503To view the registry of an NT server, one would use the Registry Editor tool. There are two
1504versions of Registry Editor:
1505
1506.:Regedt32.exe has the most menu items and more choices for the menu items. You can search
1507for keys and subkeys in the registry.
1508
1509.:Regedit.exe enables you to search for strings, values, keys, and subkeys and export keys to
1510.reg files. This feature is useful if you want to find specific data.
1511
1512For ease of use, the Registry is divided into five seperate structures that represent the Registry
1513database in its entirety. These five groups are known as Keys, and are discussed below:
1514
1515[3.0.2] In Depth Key Discussion
1516
1517HKEY_CURRENT_USER
1518This registry key contains the configuration information for the user that is currently logged in. The
1519users folders, screen colors, and control panel settings are stored here. This information is known
1520as a User Profile.
1521
1522HKEY_USERS
1523In windowsNT 3.5x, user profiles were stored locally (by default) in the
1524systemroot\system32\config directory. In NT4.0, they are stored in the systemroot\profiles
1525directory. User-Specific information is kept there, as well as common, system wide user
1526information.
1527
1528This change in storage location has been brought about to parallel the way in which Windows95
1529handles its user profiles. In earlier releases of NT, the user profile was stored as a single file -
1530either locally in the \config directory or centrally on a server. In windowsNT 4, the single user
1531profile has been broken up into a number of subdirectories located below the \profiles directory.
1532The reason for this is mainly due to the way in which the Win95 and WinNT4 operating systems
1533use the underlying directory structure to form part of their new user interface.
1534
1535A user profile is now contained within the NtUser.dat (and NtUser.dat.log) files, as well as the
1536following subdirectories:
1537
1538? Application Data: This is a place to store application data specific to this particular user.
1539? Desktop: Placing an icon or a shortcut into this folder causes the that icon or shortcut to
1540appear on the desktop of the user.
1541? Favorites: Provides a user with a personlized storage place for files, shortcuts and other
1542information.
1543? NetHood: Maintains a list of personlized network connections.
1544? Personal: Keeps track of personal documents for a particular user.
1545? PrintHood: Similar to NetHood folder, PrintHood keeps track of printers rather than network
1546connections.
1547? Recent: Contains information of recently used data.
1548? SendTo: Provides a centralized store of shortcuts and output devices.
1549? Start Menu: Contains configuration information for the users menu items.
1550? Templates: Storage location for document templates.
1551
1552HKEY_LOCAL_MACHINE
1553This key contains configuration information particular to the computer. This information is stored
1554in the systemroot\system32\config directory as persistent operating system files, with the
1555exception of the volatile hardware key.
1556
1557The information gleaned from this configuration data is used by applications, device drivers, and
1558the WindowsNT 4 operating system. The latter usage determines what system configuration data
1559to use, without respect to the user currently logged on. For this reason the
1560HKEY_LOCAL_MACHINE regsitry key is of specific importance to administrators who want to
1561support and troubleshoot NT 4.
1562
1563HKEY_LOCAL_MACHINE is probably the most important key in the registry and it contains five
1564subkeys:
1565
1566? Hardware: Database that describes the physical hardware in the computer, the way device
1567drivers use that hardware, and mappings and related data that link kernel-mode drivers with
1568various user-mode code. All data in this sub-tree is re-created everytime the system is
1569started.
1570? SAM: The security accounts manager. Security information for user and group accounts and
1571for the domains in NT 4 server.
1572? Security: Database that contains the local security policy, such as specific user rights. This
1573key is used only by the NT 4 security subsystem.
1574? Software: Pre-computer software database. This key contains data about software installed
1575on the local computer, as well as configuration information.
1576? System: Database that controls system start-up, device driver loading, NT 4 services and OS
1577behavior.
1578
1579Information about the HKEY_LOCAL_MACHINE\SAM Key
1580
1581This subtree contains the user and group accounts in the SAM database for the local computer.
1582For a computer that is running NT 4, this subtree also contains security information for the
1583domain. The information contained within the SAM registry key is what appears in the user
1584interface of the User Manager utility, as well as in the lists of users and groups that appear when
1585you make use of the Security menu commands in NT4 explorer.
1586
1587Information about the HKEY_LOCAL_MACHINE\Security key
1588
1589This subtree contains security information for the local computer. This includes aspects such as
1590assigning user rights, establishing password policies, and the membership of local groups, which
1591are configurable in User Manager.
1592
1593HKEY_CLASSES_ROOT
1594
1595The information stored here is used to open the correct application when a file is opened by using
1596Explorer and for Object Linking and Embedding. It is actually a window that reflects information
1597from the HKEY_LOCAL_MACHINE\Software subkey.
1598
1599HKEY_CURRENT_CONFIG
1600
1601The information contained in this key is to configure settings such as the software and device
1602drivers to load or the display resolution to use. This key has a software and system subkeys,
1603which keep track of configuration information.
1604
1605[3.0.3] Understanding Hives
1606
1607The registry is divided into parts called hives. These hives are mapped to a single file and a .LOG
1608file. These files are in the systemroot\system32\config directory.
1609
1610Registry Hive File Name
1611=================================================================
1612HKEY_LOCAL_MACHINE\SAM SAM and SAM.LOG
1613HKEY_LOCAL_MACHINE\SECURITY Security and Security.LOG
1614HKEY_LOCAL_MACHINE\SOFTWARE Software and Software.LOG
1615HKEY_LOCAL_MACHINE\SYSTEM System and System.ALT
1616=================================================================
1617
1618Although I am not gauranteeing that these files will be easy to understand, with a little research
1619and patience, you will learn what you want to learn. I have been asked to write a file on how to
1620decipher the contents of those files, but I have yet to decide weather I will do it or not.
1621
1622QuickNotes
1623
1624Ownership = The ownership menu item presents a dialog box that identifies the user who owns
1625the selected registry key. The owner of a key can permit another user to take ownership of a key.
1626In addition, a system administrator can assign a user the right to take ownership, or outright take
1627ownership himself.
1628
1629REGINI.EXE = This utility is a character based console application that you can use to add keys
1630to the NT registry by specifying a Registry script.
1631
1632[3.0.4] Default Registry Settings
1633
1634The Following table lists the major Registry hives and some subkeys and the DEFAULT access
1635permissions assigned:
1636
1637\\ denotes a major hive \denotes a subkey of the prior major hive
1638
1639\\HKEY_LOCAL_MACHINE
1640
1641 Admin-Full Control
1642 Everyone-Read Access
1643 System-Full Control
1644
1645 \HARDWARE
1646
1647 Admin-Full Control
1648 Everyone-Read Access
1649 System-Full Control
1650
1651 \SAM
1652
1653 Admin-Full Control
1654 Everyone-Read Access
1655 System-Full Control
1656
1657 \SECURITY
1658
1659 Admin-Special (Write DAC, Read Control)
1660 System-Full Control
1661
1662 \SOFTWARE
1663
1664 Admin-Full Control
1665 Creator Owner-Full Control
1666 Everyone-Special (Query, Set, Create, Enumerate, Notify, Delete, Read)
1667 System-Full Control
1668
1669 \SYSTEM
1670
1671 Admin-Special (Query, Set, Create, Enumerate, Notify, Delete, Read)
1672 Everyone-Read Access
1673 System-Full Control
1674
1675\\HKEY_CURRENT_USER
1676
1677 Admin-Full Control
1678 Current User-Full Control
1679 System-Full Control
1680
1681\\HKEY_USERS
1682
1683 Admin-Full Control
1684 Current User-Full Control
1685 System-Full Control
1686
1687\\HKET_CLASSES_ROOT
1688
1689 Admin-Full Control
1690 Creator Owner-Full Control
1691 Everyone-Special (Query, Set, Create, Enumerate, Notify, Delete, Read)
1692 System-Full Control
1693
1694\\HKEY_CURRENT CONFIG
1695
1696 Admin-Full Control
1697 Creator Owner-Full Control
1698 Everyone-Read Access
1699 System-Full Control
1700
1701[4.0.0] Introduction to PPTP
1702
1703Point-To-Point Tunneling Protocol (PPTP) is a protocol that allows the secure exchange of data
1704from a client to a server by forming a Virtual Private Network (VPN) via a TCP/IP based network.
1705The strong point of PPTP is its ability to provide on demand, multi-protocol support over existing
1706network infrastructure, such as the Internet. This ability would allow a company to use the Internet
1707to establish a virtual private network without the expense of a leased line.
1708
1709The technology that makes PPTP possible is an extension of the remote access Point-To-Point
1710Protocol (PPP- which is defined and documented by the Internet Engineering Task Force in RFC
17111171). PPTP technology encapsulates PPP packets into IP datagrams for transmission over
1712TCP/IP based networks. PPTP is currently a protocol draft awaiting standardization. The
1713companies involved in the PPTP forum are Microsoft, Ascend Communications, 3Com/Primary
1714Access, ECI Telematics, and US Robotics.
1715
1716[4.0.1] PPTP and Virtual Private Networking
1717
1718The Point-To-Point Tunneling Protocol is packaged with WindowsNT 4.0 Server and Workstation.
1719PC's that are running this protocol can use it to securely connect to a private network as a
1720remote access client using a public data network such as the Internet.
1721
1722A major feature in the use of PPTP is its support for virtual private networking. The best part of
1723this feature is that it supports VPN's over public-switched telephone networks (PSTNs). By using
1724PPTP a company can greatly reduce the cost of deploying a wide area, remote access solution
1725for mobile users because it provides secure and encrypted communications over existing network
1726structures like PSTNs or the Internet.
1727
1728[4.0.2] Standard PPTP Deployment
1729
1730In general practice, there are normally three computers involved in a deployment:
1731
1732? a PPTP client
1733? a Network Access Server
1734? a PPTP Server
1735
1736note: the network access server is optional, and if NOT needed for PPTP deployment. In normal
1737deployment however, they are present.
1738
1739In a typical deployment of PPTP, it begins with a remote or mobile PC that will be the PPTP
1740client. This PPTP client needs access to a private network by using a local Internet Service
1741Provider (ISP). Clients who are running the WindowsNT Server or Workstation operating systems
1742will use Dial-up networking and the Point-To-Point protocol to connect to their ISP. The client will
1743then connect to a network access server which will be located at the ISP (Network Access
1744Servers are also known as Front-End Processors (FEPs) or Point-Of-Presence servers (POPs)).
1745Once connected, the client has the ability to exchange data over the Internet. The Network
1746Access Server uses the TCP/IP protocol for the handling of all traffic.
1747
1748After the client has made the initial PPP connection to the ISP, a second Dial-Up networking call
1749is made over the existing PPP connection. Data sent using the second connection is in the form
1750of IP datagrams that contain PPP packets, referred to as encapsulated PPP. It is this second call
1751that creates the virtual private network connection to a PPTP server on the private company
1752network. This is called a tunnel.
1753
1754Tunneling is the process of exchanging data to a computer on a private network by routing them
1755over some other network. The other network routers cannot access the computer that is on the
1756private network. However, tunneling enables the routing network to transmit the packet to an
1757intermediary computer, such as a PPTP server. This PPTP server is connected to both the
1758company private network and the routing network, which is in this case, the Internet. Both the
1759PPTP client and the PPTP server use tunneling to securely transmit packets to a computer on the
1760private network.
1761
1762When the PPTP server receives a packet from the routing network (Internet), it sends it across
1763the private network to the destination computer. The PPTP server does this by processing the
1764PPTP packet to obtain the private network computer name or address information which is
1765encapsulated in the PPP packet.
1766
1767quick note: The encapsulated PPP packet can contain multi-protocol data such as TCP/IP,
1768IPX/SPX, or NetBEUI. Because the PPTP server is configured to communicate across the private
1769network by using private network protocols, it is able to understand Multi-Protocols.
1770
1771PPTP encapsulates the encrypted and compressed PPP packets into IP datagrams for
1772transmission over the Internet. These IP datagrams are routed over the Internet where they reach
1773the PPTP server. The PPTP server disassembles the IP datagram into a PPP packet and then
1774decrypts the packet using the network protocol of the private network. As mentioned earlier, the
1775network protocols that are supported by PPTP are TCP/IP, IPX/SPX and NetBEUI.
1776
1777[4.0.3] PPTP Clients
1778
1779A computer that is able to use the PPTP protocol can connect to a PPTP server two different
1780ways:
1781
1782? By using an ISP's network access server that supports inbound PPP connections.
1783? By using a physical TCP/IP-enabled LAN connection to connect to a PPTP server.
1784
1785PPTP clients attempting to use an ISP's network access server must be properly configured with
1786a modem and a VPN device to make the seperate connections to the ISP and the PPTP server.
1787The first connection is dial-up connection utilizing the PPP protocol over the modem to an Internet
1788Service Provider. The second connection is a VPN connection using PPTP, over the modem and
1789through the ISP. The second connection requires the first connection because the tunnel between
1790the VPN devices is established by using the modem and PPP connections to the internet.
1791
1792The exception to this two connection process is using PPTP to create a virtual private network
1793between computers physically connected to a LAN. In this scenario the client is already
1794connected to a network and only uses Dial-Up networking with a VPN device to create the
1795connection to a PPTP server on the LAN.
1796
1797PPTP packets from a remote PPTP client and a local LAN PPTP client are processed differently.
1798A PPTP packet from a remote client is placed on the telecommunication device physical media,
1799while the PPTP packet from a LAN PPTP client is placed on the network adapter physical media.
1800
1801[4.0.4] PPTP Architecture
1802
1803This next area discusses the architecture of PPTP under Windows NT Server 4.0 and NT
1804Workstation 4.0. The following section covers:
1805
1806? PPP Protocol
1807? PPTP Control Connection
1808? PPTP Data Tunneling
1809
1810Architecture Overview:
1811The secure communication that is established using PPTP typically involves three processes,
1812each of which requires successful completion of the previous process. This will now explain these
1813processes and how they work:
1814
1815PPP Connection and Communication: A PPTP client utilizes PPP to connect to an ISP by using a
1816standard telephone line or ISDN line. This connection uses the PPP protocol to establish the
1817connection and encrypt data packets.
1818
1819PPTP Control Connection: Using the connection to the Internet established by the PPP protocol,
1820the PPTP protocol creates a control connection from the PPTP client to a PPTP server on the
1821Internet. This connection uses TCP to establish communication and is called a PPTP Tunnel.
1822
1823PPTP Data Tunneling: The PPTP protocol creates IP datagrams containing encrypted PPP
1824packets which are then sent through the PPTP tunnel to the PPTP server. The PPTP server
1825disassembles the IP datagrams and decrypts the PPP packets, and the routes the decrypted
1826packet to the private network.
1827
1828PPP Protocol:
1829
1830The are will not cover in depth information about PPP, it will cover the role PPP plays in a PPTP
1831environment. PPP is a remote access protocol used by PPTP to send data across TCP/IP based
1832networks. PPP encapsulates IP, IPX, and NetBEUI packets between PPP frames and sends the
1833encapsulated packets by creating a point-to-point link between the sending and receiving
1834computers.
1835
1836Most PPTP sessions are started by a client dialing up an ISP network access server. The PPP
1837protocol is used to create the dial-up connection between the client and network access server
1838and performs the folloing functions:
1839
1840? Establishes and ends the physical connection. The PPP protocol uses a sequence defined in
1841RFC 1661 to establish and maintain connections between remote computers.
1842? Authenticates Users. PPTP clients are authenticated by using PPP. Clear text, encrypted or
1843MS CHAP can be used by the PPP protocol.
1844? Creates PPP datagrams that contain encrypted IPX, NetBEUI, or TCP/IP packets.
1845
1846PPTP Control Connection:
1847
1848The PPTP protocol specifies a series of messages that are used for session control. These
1849messages are sent between a PPTP client and a PPTP server. The control messages establish,
1850maintain and end the PPTP tunnel. The following list present the primary control messages used
1851to establish and maintain the PPTP session.
1852
1853 Message Type Purpose
1854PPTP_START_SESSION_REQUEST Starts Session
1855PPTP_START_SESSION_REPLY Replies to Start Session Request
1856PPTP_ECHO_REQUEST Maintains Session
1857PPTP_ECHO_REPLY Replies to Maintain Session Request
1858PPTP_WAN_ERROR_NOTIFY Reports an error in the PPP connection
1859PPTP_SET_LINK_INFO Configures PPTP Client/Server Connection
1860PPTP_STOP_SESSION_REQUEST Ends Session
1861PPTP_STOP_SESSION_REPLY Replies to End Session Request
1862
1863The control messages are sent inside of control packets in a TCP datagram. One TCP
1864connection is enabled between the PPTP client and Server. This path is used to send and receive
1865control messages. The datagram contains a PPP header, a TCP Header, a PPTP Control
1866message and appropriate trailers. The construction is as follows
1867
1868-----------------------------------
1869PPP Delivery Header
1870-----------------------------------
1871IP Header
1872-----------------------------------
1873PPTP Control Message
1874-----------------------------------
1875Trailers
1876-----------------------------------
1877
1878PPTP Data Transmission
1879
1880After the PPTP Tunnel has been created, user data is transmitted between the client and PPTP
1881server. Data is sent in IP Datagrams containing PPP packets. The IP datagram is created using a
1882modified version of the Generic Routing Encapsulation (GRE) protocol (GRE is defined in RFC
18831701 and 1702). The structure of the IP Datagram is as follows:
1884
1885---------------------------------------------------
1886PPP Delivery Header
1887---------------------------------------------------
1888IP Header
1889---------------------------------------------------
1890GRE Header
1891---------------------------------------------------
1892PPP Header
1893---------------------------------------------------
1894IP Header
1895---------------------------------------------------
1896TCP Header
1897---------------------------------------------------
1898Data
1899---------------------------------------------------
1900
1901By paying attention to the construction of the packet, you can see how it would be able to be
1902transmitted over the Internet as headers are stripped off. The PPP Delivery header provides
1903information necessary for the datagram to traverse the Internet. The GRE header is used to
1904encapsulate the PPP packet within the IP Datagram. The PPP packet is created by RAS. The
1905PPP Packet is encrypted and if intercepted, would be unintelligible.
1906
1907[4.0.5] Understanding PPTP Security
1908
1909PPTP uses the strict authentication and encryption security available to computers running RAS
1910under WindowsNT Server version 4.0. PPTP can also protect the PPTP server and private
1911network by ignoring all but PPTP traffic. Despite this security, it is easy to configure a firewall to
1912allow PPTP to access the network.
1913
1914Authentication: Initial dial-in authentication may be required by an ISP network access server. If
1915this Authentication is required, it is strictly to log on to the ISP, it is not related to Windows NT
1916based Authentication. A PPTP server is a gateway to your network, and as such it requires
1917standard WindowsNT based logon. All PPTP clients must provide a user name and password.
1918Therefore, remote access logon using a PC running under NT server or Workstation is as secure
1919as logging on from a PC connected to a LAN (theoretically). Authentication of remote PPTP
1920clients is done by using the same PPP authentication methods used for any RAS client dialing
1921directly into an NT Server. Because of this, it fully supports MS-CHAP (Microsoft Challenge
1922Handshake Authentication Protocol which uses the MD4 hash as well as earlier LAN Manager
1923methods.)
1924
1925Access Control: After Authentication, all access to the private LAN continues to use existing NT
1926based security structures. Access to resources on NTFS drives or to other network resources
1927require the proper permissions, just as if you were connected directly to the LAN.
1928
1929Data Encryption: For data encryption, PPTP uses the RAS "shared-secret" encryption process. It
1930is referred to as a shared-secret because both ends of the connection share the encryption key.
1931Under Microsoft’s implementation of RAS, the shared secret is the user password (Other
1932methods include public key encryption). PPTP uses the PPP encryption and PPP compression
1933schemes. The CCP (Compression Control Protocol) is used to negotiate the encryption used. The
1934username and password is available to the server and supplied by the client. An encryption key is
1935generated using a hash of the password stored on both the client and server. The RSA RC4
1936standard is used to create this 40-bit (128-bit inside the US and Canada is available) session key
1937based on the client password. This key is then used to encrypt and decrypt all data exchanged
1938between the PPTP client and server. The data in PPP packets is encrypted. The PPP packet
1939containing the block of encrypted data is then stuffed into a larger IP datagram for routing.
1940
1941PPTP Packet Filtering: Network security from intruders can be enhanced by enabling PPTP
1942filtering on the PPTP server. When PPTP filtering is enabled, the PPTP server on the private
1943network accepts and routes only PPTP packets. This prevents ALL other packet types from
1944entering the network. PPTP traffic uses port 1723.
1945
1946[4.0.6] PPTP and the Registry
1947
1948This following is a list of Windows NT Registry Keys where user defined PPTP information can be
1949found:
1950
1951KEY: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RASPPTPE\
1952 Parameters\Configuration
1953
1954Values: AuthenticateIncomingCalls
1955 DataType = REG_WORD
1956 Range = 0 - 1
1957 Default = 0
1958
1959Set this value to 1 to force PPTP to accept calls only from IP addresses listed in the
1960PeerClientIPAddresses registry value. If AuthenticateIncomingCalls is set to 1 and there are no
1961addresses in PeerClientIPAddresses, the no clients will be able to connect.
1962
1963 PeerClientIPAddresses
1964 DataType = REG_MULTI_SZ
1965 Range = The format is a valid IP address
1966
1967This parameter is a list of IP addresses the server will accept connections from.
1968
1969KEY: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\<adapter name>\
1970 Parameters\Tcpip
1971
1972Values: DontAddDefaultGateway
1973 DataType = REG_WORD
1974 Range = 0 - 1
1975 Default = 1
1976
1977When PPTP is installed, a default route is made for each LAN adapter. This parameter will
1978disable the default route on the corporate LAN adapter.
1979
1980 PPTPFiltering
1981 Key: <adaptername.\Paramters\tcpip
1982 ValueType: REG_WORD
1983 Valid Range: 0 - 1
1984 Default = 0
1985
1986This parameter controls whether PPTP filtering is enabled or not.
1987
1988 PPTPTcpMaxDataRetransmissions
1989 Key: Tcpip\Parameters
1990 ValueType: REG_WORD - Number of times to retransmit a PPTP packet.
1991 Valid Range: 0 - 0xFFFFFFFF
1992 Default: 9
1993
1994This setting control how many times PPTP will retransmit a packet.
1995
1996[4.0.7] Special Security Update
1997
1998SPECIAL REVISION: As a last minute revision to the lecture. A flaw has been discovered in the
1999PPTP architecture. It turns out that if you send a that if you send a pptp start session request with
2000an invalid packet length in the pptp packet header that it will crash an NT box and cause the NT
2001server to do a CoreDump. Fragments of code for a DoS attack package are flying, and the Demitri
2002team should have a completed DoS Attack program released soon. This program is released, of
2003course, for network administrators wanting to know how the bug works.
2004
2005[5.0.0] TCP/IP Commands as Tools
2006
2007 This is list of the most commonly used TCP/IP command line tools that are used to
2008explore and find out information from a network. These tools will be referred to later on in this
2009document, so its usage and function will not be explained later. Please note that not all of these
2010switches remain the same across different TCP/IP stacks. The Microsoft TCP/IP stack is almost
2011always different than most switches used on Unix systems.
2012
2013[5.0.1] The Arp Command
2014
2015The arp command will display internet to ethernet (IP to MAC) address translations which is
2016normally handled by the arp protocol. When the hostname is the only parameter, this command
2017will display the currect ARP entry for that hostname.
2018
2019Usage: arp hostname
2020
2021Switches: -a Displays current ARP entries by interrogating the current
2022 protocol data. If inet_addr is specified, the IP and Physical
2023 addresses for only the specified computer are displayed. If
2024 more than one network interface uses ARP, entries for each ARP
2025 table are displayed.
2026 -g Same as -a.
2027 inet_addr Specifies an internet address.
2028 -N if_addr Displays the ARP entries for the network interface specified
2029 by if_addr.
2030 -d Deletes the host specified by inet_addr.
2031 -s Adds the host and associates the Internet address inet_addr
2032 with the Physical address eth_addr. The Physical address is
2033 given as 6 hexadecimal bytes separated by hyphens. The entry
2034 is permanent.
2035 eth_addr Specifies a physical address.
2036 if_addr If present, this specifies the Internet address of the
2037 interface whose address translation table should be modified.
2038 If not present, the first applicable interface will be used.
2039
2040
2041[5.0.2] The Traceroute Command
2042
2043The traceroute command is used to trace the route that a packet takes to reach its destination.
2044This command works by using the time to live (TTL) filed in the IP packet.
2045
2046Usage: tracert IP or Hostname
2047
2048Switches: -d Do not resolve addresses to hostnames.
2049 -h maximum_hops Maximum number of hops to search for target.
2050 -j host-list Loose source route along host-list.
2051 -w timeout Wait timeout milliseconds for each reply.
2052
2053[5.0.3] The Netstat Command
2054
2055This command is used to query the network subsystem regarding certain types of information.
2056Different types of information will be received depending on the switches used in conjunction with
2057this command.
2058
2059Usage: netstat [switch]
2060
2061Switches: -A Shows the addresses of any associated protocol control blocks.
2062 -a Will show the status of all sockets. Sockets associated with network
2063 server processes are normally not shown.
2064 -i Shows the state of the network interfaces.
2065 -m Prints the network memory usage.
2066 -n Causes netstat to show actual addresses as opposed to hostnames or
2067 network names.
2068 -r Prints the routing table.
2069 -s Tells netstat to show the per protocol statistics.
2070 -t Replaces the queue length information with timer information.
2071
2072[5.0.4] The Finger Command
2073
2074By default, finger will list the login name, full name, terminal name, and write status (shown as a
2075"*" before the terminal name if write permission is denied), idle time, login time, office location,
2076and phone number (if known) for each current user connected to the network.
2077
2078Usage: finger username@domain
2079
2080Switches: -b Brief output format
2081 -f Supresses the printing of the header line.
2082 -i Provides a quick list of users with idle time.
2083 -l Forces long output format.
2084 -p Supresses printing of the .plan file (if present)
2085 -q Provides a quick list of users.
2086 -s Forces short output form.
2087 -w Forces narrow output form.
2088
2089[5.0.5] The Ping Command
2090
2091The ping (Packet Internet Groper) is used to send ICMP (Internet Control Message Protocol)
2092packets from one host to another. Ping transmits packets using the ICMP ECHO_REQUEST
2093command and expects an ICMP ECHO_REPLY.
2094
2095Usage: ping IP address or Hostname
2096
2097Switches: -t Ping the specifed host until interrupted.
2098 -a Resolve addresses to hostnames.
2099 -n count Number of echo requests to send.
2100 -l size Send buffer size.
2101 -f Set Don't Fragment flag in packet.
2102 -i TTL Time To Live.
2103 -v TOS Type Of Service.
2104 -r count Record route for count hops.
2105 -s count Timestamp for count hops.
2106 -j host-list Loose source route along host-list.
2107 -k host-list Strict source route along host-list.
2108 -w timeout Timeout in milliseconds to wait for each reply.
2109
2110[5.0.6] The Nbtstat Command
2111
2112Can be used to query the network concerning NetBIOS information. It can also be useful for
2113purging the NetBIOS cache and reloading the LMHOSTS file. This one command can be
2114extremely useful when performing security audits. When one knows how to interpret the
2115information, it can reveal more than one might think.
2116
2117Usage: nbtstat [-a RemoteName] [-A IP_address] [-c] [-n] [-R] [-r] [-S] [-s] [interval]
2118
2119Switches -a Lists the remote computer's name table given its host name.
2120 -A Lists the remote computer's name table given its IP address.
2121 -c Lists the remote name cache including the IP addresses.
2122 Lists the remote name cache including the IP addresses Lists local
2123NetBIOS
2124 names. Lists names resolved by broadcast and via WINS Purges and
2125reloads the
2126 remote cache name table Lists sessions table with the destination IP
2127addresses
2128 Lists sessions table converting destination IP addresses to host names via
2129the
2130 hosts file.
2131
2132 -n Lists local NetBIOS names.
2133 -r Lists names resolved by broadcast and via WINS.
2134 -R Purges and reloads the remote cache name table.
2135 -S Lists sessions table with the destination IP addresses.
2136 -s Lists sessions table converting destination IP addresses to host names via
2137the
2138 hosts file.
2139 interval This will redisplay the selected statistics, pausing for the number of
2140 seconds you
2141 choose as "interval" between each listing. Press CTRL+C to stop.
2142
2143Notes on NBTSTAT
2144
2145The column headings generated by NBTSTAT have the following meanings:
2146
2147Input
2148 Number of bytes received.
2149Output
2150 Number of bytes sent.
2151In/Out
2152 Whether the connection is from the computer (outbound) or from another system to
2153 the local computer (inbound).
2154Life
2155 The remaining time that a name table cache entry will "live" before your computer
2156 purges it.
2157Local Name
2158 The local NetBIOS name given to the connection.
2159Remote Host
2160 The name or IP address of the remote host.
2161Type
2162 A name can have one of two types: unique or group.
2163 The last byte of the 16 character NetBIOS name often means something because
2164 the same name can be present multiple times on the same computer. This shows
2165 the last byte of the name converted into hex.
2166State
2167 Your NetBIOS connections will be shown in one of the following "states":
2168
2169
2170 State Meaning
2171
2172 Accepting An incoming connection is in process.
2173 Associated The endpoint for a connection has been created and your computer has
2174ssociated it with an IP address.
2175 Connected This is a good state! It means you're connected to the remote resource.
2176 Connecting Your session is trying to resolve the name-to-IP address mapping of the
2177destination resource.
2178 Disconnected Your computer requested a disconnect, and it is waiting for the remote
2179computer to do so.
2180 Disconnecting Your connection is ending.
2181 Idle The remote computer has been opened in the current session, but is currently
2182not accepting connections.
2183 Inbound An inbound session is trying to connect.
2184 Listening The remote computer is available.
2185 Outbound Your session is creating the TCP connection.
2186 Reconnecting If your connection failed on the first attempt, it will display this state as it tries
2187to reconnect.
2188
2189Name Number Type Usage
2190=========================================================================
2191<computername> 00 U Workstation Service
2192<computername> 01 U Messenger Service
2193<\\_MSBROWSE_> 01 G Master Browser
2194<computername> 03 U Messenger Service
2195<computername> 06 U RAS Server Service
2196<computername> 1F U NetDDE Service
2197<computername> 20 U File Server Service
2198<computername> 21 U RAS Client Service
2199<computername> 22 U Exchange Interchange
2200<computername> 23 U Exchange Store
2201<computername> 24 U Exchange Directory
2202<computername> 30 U Modem Sharing Server Service
2203<computername> 31 U Modem Sharing Client Service
2204<computername> 43 U SMS Client Remote Control
2205<computername> 44 U SMS Admin Remote Control Tool
2206<computername> 45 U SMS Client Remote Chat
2207<computername> 46 U SMS Client Remote Transfer
2208<computername> 4C U DEC Pathworks TCPIP Service
2209<computername> 52 U DEC Pathworks TCPIP Service
2210<computername> 87 U Exchange MTA
2211<computername> 6A U Exchange IMC
2212<computername> BE U Network Monitor Agent
2213<computername> BF U Network Monitor Apps
2214<username> 03 U Messenger Service
2215<domain> 00 G Domain Name
2216<domain> 1B U Domain Master Browser
2217<domain> 1C G Domain Controllers
2218<domain> 1D U Master Browser
2219<domain> 1E G Browser Service Elections
2220<INet~Services> 1C G Internet Information Server
2221<IS~Computer_name> 00 U Internet Information Server
2222<computername> [2B] U Lotus Notes Server
2223IRISMULTICAST [2F] G Lotus Notes
2224IRISNAMESERVER [33] G Lotus Notes
2225Forte_$ND800ZA [20] U DCA Irmalan Gateway Service
2226
2227Unique (U): The name may have only one IP address assigned to it. On a network device,
2228multiple occurences of a single name may appear to be registered, but the suffix will be unique,
2229making the entire name unique.
2230
2231Group (G): A normal group; the single name may exist with many IP addresses.
2232
2233Multihomed (M): The name is unique, but due to multiple network interfaces on the same
2234computer, this configuration is necessary to permit the registration. Maximum number of
2235addresses is 25.
2236
2237Internet Group (I): This is a special configuration of the group name used to manage WinNT
2238domain names.
2239
2240Domain Name (D): New in NT 4.0
2241
2242[5.0.7] The IpConfig Command
2243
2244The ipconfig command will give you information about your current TCP/IP configuration.
2245Information such as IP address, default gateway, subnet mask, etc can all be retrieved using this
2246command.
2247
2248Usage: ipconfig [/? | /all | /release [adapter] | /renew [adapter]]
2249
2250Switches: /? Display this help message.
2251 /all Display full configuration information.
2252 /release Release the IP address for the specified adapter.
2253 /renew Renew the IP address for the specified adapter.
2254
2255[5.0.8] The Telnet Command
2256
2257Technically, telnet is a protocol. This means it is a language that computer use to communicate
2258with one another in a particular way. From your point of view, Telnet is a program that lets you
2259login to a site on the Internet through your connection to Teleport. It is a terminal emulation
2260program, meaning that when you connect to the remote site, your computer functions as a
2261terminal for that computer.
2262
2263Once the connection is made, you can use your computer to access information, run programs,
2264edit files, and otherwise use whatever resources are available on the other computer. What is
2265available depends on the computer you connect to. Most of the times, if you type '?' or 'help', you
2266would normally receive some type of information, menu options, etc.
2267
2268 Note: telnet connections give you command-line access only. In other
2269 words, instead of being able to use buttons and menus as you do with a
2270 graphical interface, you have to type commands. However, telnet allows
2271 you to use certain utilities and resources you cannot access with your
2272 other Internet applications.
2273
2274Usage: telnet hostname or IP address port(optional)
2275
2276[6.0.0] NT Security
2277
2278[6.0.1] The Logon Process
2279
2280WinLogon
2281
2282Users must log on to a Windows NT machine in order to use that NT based machine or network.
2283The logon process itself cannot be bypassed, it is mandatory. Once the user has logged on, an
2284access token is created (this token will be discussed in more detail later). This token contains
2285user specific security information, such as: security identifier, group identifiers, user rights and
2286permissions. The user, as well as all processes spawned by the user are identified to the system
2287with this token.
2288
2289The first step in the WinLogon process is something we are all familiar with, CTRL+ALT+DEL.
2290This is NT's default Security Attention Sequence (SAS - The SAS key combo can be changed.
2291We will also discuss that later.). This SAS is a signal to the operating system that someone is
2292trying to logon. After the SAS is triggered, all user mode applications pause until the security
2293operation completes or is cancelled. (Note: The SAS is not just a logon operation, this same key
2294combination can be used for logging on, logging off, changing a password or locking the
2295workstation.) The pausing, or closing, of all user mode applications during SAS is a security
2296feature that most people take for granted and dont understand. Due to this pausing of
2297applications, logon related trojan viruses are stopped, keyloggers (programs that run in memory,
2298keeping track of keystrokes, therefor recording someones password) are stopped as well.
2299
2300The user name is not case sensitive but the password is.
2301
2302After typing in your information and clicking OK (or pressing enter), the WinLogon process
2303supplies the information to the security subsystem, which in turn compares the information to the
2304Security Accounts Manager (SAM). If the information is compliant with the information in the
2305SAM, an access token is created for the user. The WinLogon takes the access token and passes
2306it onto the Win32 subsytem, which in turn starts the operating systems shell. The shell, as well as
2307all other spawned processes will receive a token. This token is not only used for security, but also
2308allows NTs auditing and logging features to track user usage and access of network resources.
2309
2310Note: All of the logon components are located in a file known as the Graphical Indetification and
2311Authentication (GINA) module, specifically MSGINA.DLL. Under certain conditions, this file can
2312be replaced, which is how you would change the SAS key combination.
2313
2314For fine tuning of the WinLogon process, you can refer to the registry. All of the options for the
2315WinLogon process are contained in the
2316HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon area.
2317You can also fine tune the process by using the Policy Editor.
2318
2319Logging on to a Domain
2320
2321If an NT machine is a participant on a Domain, you would not only need to login to the local
2322machine, but the Domain as well. If a computer is a member of a Domain, the WinLogon process
2323is replaced by the NetLogon process.
2324
2325[6.0.2] Security Architecture Components
2326
2327Local Security Authority (LSA): Also known as the security subsystem, it is the central portion of
2328NT security. It handles local security policies and user authentication. The LSA also handles
2329generating and logging audit messages.
2330
2331Security Accounts Manager (SAM): The SAM handles user and group accounts, and provides
2332user authentication for the LSA.
2333
2334Security Reference Monitor (SRM): The SRM is in charge of enforcing and assuring access
2335validation and auditing for the LSA. It references user account information as the user attempts to
2336access resources.
2337
2338[6.0.3] Introduction to Securing an NT Box
2339
2340Abstract
2341Microsoft Windows NT operating system provides several security features. However, the default
2342out-of-the-box configuration is highly relaxed, especially on the Workstation product. This is
2343because the operating system is sold as a shrink-wrapped product with an assumption that an
2344average customer may not want to worry about a highly restrained but secure system on their
2345desktop.
2346
2347A particular installation's requirements can differ significantly from another. Therefore, it is
2348necessary for individual customers to evaluate their particular environment and requirements
2349before implementing a security configuration. This is also because implementing security settings
2350can impact system configuration. Certain applications installed on Windows NT may require
2351more relaxed settings to function properly than others because of the nature of the product.
2352Customers are therefore advised to careful evaluate recommendations in the context of their
2353system configurations and usage.
2354
2355If you install a Windows NT machine as a web server or a firewall, you should tighten up the
2356security on that box. Ordinary machines on your internal network are less accessible than a
2357machine the Internet. A machine accessible from the Internet is more vulnerable and likely to be
2358attacked. Securing the machine gives you a bastion host. Some of the things you should do
2359include:
2360
2361? Remove all protocol stacks except TCP/IP, since IP is the only protocol that runs on the
2362Internet
2363? Remove unnecessary network bindings
2364? Disable all unnecessary accounts, like guest
2365? Remove share permissions and default shares
2366? Remove network access for everyone (User Manger -> Policies ->User rights, "Access
2367this computer from the network")
2368? Disable unnecessary services
2369? Enable audit logging
2370? Track the audit information
2371
2372[6.0.4] Physical Security Considerations
2373Take the precautions you would with any piece of valuable equipment to protect against casual
2374theft. This step can include locking the room the computer is in when no one is there to keep an
2375eye on it, or using a locked cable to attach the unit to a wall. You might also want to establish
2376procedures for moving or repairing the computer so that the computer or its components cannot
2377be taken under false pretenses.
2378
2379Use a surge protector or power conditioner to protect the computer and its peripherals from
2380power spikes. Also, perform regular disk scans and defragmentation to isolate bad sectors and to
2381maintain the highest possible disk performance.
2382
2383As with minimal security, the computer should be protected as any valuable equipment would be.
2384Generally, this involves keeping the computer in a building that is locked to unauthorized users,
2385as most homes and offices are. In some instances you might want to use a cable and lock to
2386secure the computer to its location. If the computer has a physical lock, you can lock it and keep
2387the key in a safe place for additional security. However, if the key is lost or inaccessible, an
2388authorized user might be unable to work on the computer.
2389
2390You might choose to keep unauthorized users away from the power or reset switches on the
2391computer, particularly if your computer's rights policy denies them the right to shut down the
2392computer. The most secure computers (other than those in locked and guarded rooms) expose
2393only the computer's keyboard, monitor, mouse, and (when appropriate) printer to users. The CPU
2394and removable media drives can be locked away where only specifically authorized personnel
2395can access them.
2396
2397[6.0.5] Backups
2398Regular backups protect your data from hardware failures and honest mistakes, as well as from
2399viruses and other malicious mischief. The Windows NT Backup utility is described in Chapter 6,
2400"Backing Up and Restoring Network Files" in Microsoft Windows NT Server Concepts and
2401Planning. For procedural information, see Help.
2402
2403Obviously, files must be read to be backed up, and they must be written to be restored. Backup
2404privileges should be limited to administrators and backup operators—people to whom you are
2405comfortable giving read and write access on all files.
2406
2407[6.0.6] Networks and Security
2408If the network is entirely contained in a secure building, the risk of unauthorized taps is minimized
2409or eliminated. If the cabling must pass through unsecured areas, use optical fiber links rather than
2410twisted pair to foil attempts to tap the wire and collect transmitted data.
2411
2412[6.0.7] Restricting the Boot Process
2413Most personal computers today can start a number of different operating systems. For example,
2414even if you normally start Windows NT from the C: drive, someone could select another version
2415of Windows on another drive, including a floppy drive or CD-ROM drive. If this happens, security
2416precautions you have taken within your normal version of Windows NT might be circumvented.
2417
2418In general, you should install only those operating systems that you want to be used on the
2419computer you are setting up. For a highly secure system, this will probably mean installing one
2420version of Windows NT. However, you must still protect the CPU physically to ensure that no
2421other operating system is loaded. Depending on your circumstances, you might choose to
2422remove the floppy drive or drives. In some computers you can disable booting from the floppy
2423drive by setting switches or jumpers inside the CPU. If you use hardware settings to disable
2424booting from the floppy drive, you might want to lock the computer case (if possible) or lock the
2425machine in a cabinet with a hole in the front to provide access to the floppy drive. If the CPU is in
2426a locked area away from the keyboard and monitor, drives cannot be added or hardware settings
2427changed for the purpose of starting from another operating system. Another simple setting is to
2428edit the boot.ini file such that the boot timeout is 0 seconds; this will make hard for the user to
2429boot to another system if one exists.
2430
2431On many hardware platforms, the system can be protected using a power-on password. A power-
2432on password prevents unauthorized personnel from starting an operating system other than
2433Windows NT, which would compromise system security. Power-on passwords are a function of
2434the computer hardware, not the operating system software. Therefore the procedure for setting
2435up the power-on password depends on the type of computer and is available in the vendor's
2436documentation supplied with the system.
2437
2438[6.0.8] Security Steps for an NT Operating System
2439
2440[6.0.9] Install Latest Service Pack and applicable hot-fixes
2441 Completed Not implemented Not applicable
2442STATUS
2443
2444Install the latest recommended Microsoft Service Pack for the NT operating system. The
2445applicable hot-fixes should also be installed. Generally not all hot-fixes are required. Also the
2446order in which hot-fixes are installed is very important, as later hot-fixes sometimes supersede
2447earlier hot-fixes.
2448
2449ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40
2450
2451[6.1.0] Display a Legal Notice Before Log On
2452 Completed Not implemented Not applicable
2453STATUS
2454Windows NT can display a message box with the caption and text of your choice before a user
2455logs on. Many organizations use this message box to display a warning message that notifies
2456potential users that they can be held legally liable if they attempt to use the computer without
2457having been properly authorized to do so. The absence of such a notice could be construed as an
2458invitation, without restriction, to enter and browse the system.
2459
2460The log on notice can also be used in settings (such as an information kiosk) where users might
2461require instruction on how to supply a user name and password for the appropriate account.
2462To display a legal notice, use the Registry Editor to create or assign the following registry key
2463values on the workstation to be protected:
2464
2465Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2466Key: \Microsoft\Windows NT\Current Version\Winlogon
2467Name: LegalNoticeCaption
2468Type: REG_SZ
2469Value: Whatever you want for the title of the message box
2470Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2471Key: Microsoft\Windows NT\Current Version\Winlogon
2472Name: LegalNoticeText
2473Type: REG_SZ
2474Value: Whatever you want for the text of the message box
2475
2476The changes take effect the next time the computer is started. You might want to update the
2477Emergency Repair Disk to reflect these changes.
2478Example:
2479Welcome to the XYZ Information Kiosk
2480Log on using account name Guest and password XYZCorp.
2481Authorized Users Only
2482This system is for the use of authorized users only. Individuals using this computing system
2483without authority, or in excess of their authority, are subject to having all of their activities on this
2484system monitored and recorded by system personnel. In the course of monitoring individuals
2485improperly using this system, or in the course of system maintenance, the activities of authorized
2486users may be monitored. Anyone using this system expressly consents to such monitoring and is
2487advised that if such monitoring reveals possible evidence of criminal activity, system personnel
2488may provide the evidence of such monitoring to law enforcement officials.
2489
2490[6.1.1] Rename Administrative Accounts
2491 Completed Not implemented Not applicable
2492STATUS
2493
2494It is a good idea to rename the built-in Administrator account to something less obvious. This
2495powerful account is the one account that can never be locked out due to repeated failed log on
2496attempts, and consequently is attractive to hackers who try to break in by repeatedly guessing
2497passwords. By renaming the account, you force hackers to guess the account name as well as
2498the password.
2499
2500Make the following changes:
2501? Remove right "LOG ON FROM THE NETWORK" from Administrator's group
2502? Add right "LOG ON FROM THE NETWORK" for individuals who are administrators
2503? Enable auditing of failed login attempts
2504? Lock out users for more than 5 login failures
2505? Require password of at least 8 characters
2506
2507
2508[6.1.2] Disable Guest Account
2509 Completed Not implemented Not applicable
2510STATUS
2511
2512Disable Guest account and remove all rights (note: if using with Internet Information Server then
2513ensure that web user account has permission to access appropriate directories and the right to
2514"LOG ON LOCALLY"
2515
2516Limited access can be permitted for casual users through the built-in Guest account. If the
2517computer is for public use, the Guest account can be used for public log-ons. Prohibit Guest from
2518writing or deleting any files, directories, or registry keys (with the possible exception of a directory
2519where information can be left).
2520In a standard security configuration, a computer that allows Guest access can also be used by
2521other users for files that they don't want accessible to the general public. These users can log on
2522with their own user names and access files in directories on which they have set the appropriate
2523permissions. They will want to be especially careful to log off or lock the workstation before they
2524leave it.
2525
2526[6.1.3] Logging Off or Locking the Workstation
2527 Completed Not implemented Not applicable
2528STATUS
2529
2530Users should either log off or lock the workstation if they will be away from the computer for any
2531length of time. Logging off allows other users to log on (if they know the password to an account);
2532locking the workstation does not. The workstation can be set to lock automatically if it is not used
2533for a set period of time by using any 32-bit screen saver with the Password Protected option. For
2534information about setting up screen savers, see Help.
2535
2536? Install password protected screen saver that automatically starts if workstation is not
2537used for 5-15 minutes
2538
2539[6.1.4] Allowing Only Logged-On Users to Shut Down the Computer
2540 Completed Not implemented Not applicable
2541STATUS
2542
2543Normally, you can shut down a computer running Windows NT Workstation without logging on by
2544choosing Shutdown in the Logon dialog box. This is appropriate where users can access the
2545computer's operational switches; otherwise, they might tend to turn off the computer's power or
2546reset it without properly shutting down Windows NT Workstation. However, you can remove this
2547feature if the CPU is locked away. (This step is not required for Windows NT Server, because it is
2548configured this way by default.)
2549
2550To require users to log on before shutting down the computer, use the Registry Editor to create or
2551assign the following Registry key value:
2552
2553Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2554Key: \Microsoft\Windows NT\Current Version\Winlogon
2555Name: ShutdownWithoutLogon
2556Type: REG_SZ
2557Value: 0
2558
2559The changes will take effect the next time the computer is started. You might want to update the
2560Emergency Repair Disk to reflect these changes.
2561
2562[6.1.5] Hiding the Last User Name
2563 Completed Not implemented Not applicable
2564STATUS
2565
2566By default, Windows NT places the user name of the last user to log on the computer in the User
2567name text box of the Logon dialog box. This makes it more convenient for the most frequent user
2568to log on. To help keep user names secret, you can prevent Windows NT from displaying the user
2569name from the last log on. This is especially important if a computer that is generally accessible is
2570being used for the (renamed) built-in Administrator account.
2571
2572
2573
2574To prevent display of a user name in the Logon dialog box, use the Registry Editor to create or
2575assign the following registry key value:
2576
2577Hive: HKEY_LOCAL_MACHINE\SOFTWARE
2578Key: \Microsoft\Windows NT\Current Version\Winlogon
2579Name: DontDisplayLastUserName
2580Type: REG_SZ
2581Value: 1
2582
2583[6.1.6] Restricting Anonymous network access to Registry
2584 Completed Not implemented Not applicable
2585STATUS
2586
2587Windows NT version 4.0 Service Pack 3 includes a security enhancement that restricts
2588anonymous (null session) logons when they connect to specific named pipes including the one for
2589Registry.
2590There is a registry key value that defines the list of named pipes that are "exempt" from this
2591restriction. The key value is:
2592
2593Hive: HKEY_LOCAL_MACHINE\SYSTEM
2594Key: System\CurrentControlSet\Services\LanManServer\Parameters
2595Name: NullSessionPipes
2596Type: REG_MULTI_SZ
2597Value: Add or Remove names from the list as required by the configuration.
2598
2599Please refer to Knowledge Base article Q143138 for more details.
2600
2601[6.1.7] Restricting Anonymous network access to lookup account names and network
2602shares
2603 Completed Not implemented Not applicable
2604STATUS
2605
2606Windows NT has a feature where anonymous logon users can list domain user names and
2607enumerate share names. Customers who want enhanced security have requested the ability to
2608optionally restrict this functionality. Windows NT 4.0 Service Pack 3 and a hotfix for Windows NT
26093.51 provide a mechanism for administrators to restrict the ability for anonymous logon users
2610(also known as NULL session connections) to list account names and enumerate share names.
2611Listing account names from Domain Controllers is required by the Windows NT ACL editor, for
2612example, to obtain the list of users and groups to select who a user wants to grant access rights.
2613Listing account names is also used by Windows NT Explorer to select from list of users and
2614groups to grant access to a share.
2615The registry key value to set for enabling this feature is:
2616
2617
2618Hive: HKEY_LOCAL_MACHINE\SYSTEM
2619Key: System\CurrentControlSet\Control\LSA
2620Name: RestrictAnonymous
2621Type: REG_DWORD
2622Value: 1.
2623
2624This enhancement is part of Windows NT version 4.0 Service Pack 3. A hot fix for it is also
2625provided for Windows NT version 3.51. Please refer to Knowledge Base article Q143474 for
2626more details on this.
2627
2628[6.1.8] Enforcing strong user passwords
2629 Completed Not implemented Not applicable
2630STATUS
2631
2632Windows NT 4.0 Service Pack 2 and later includes a password filter DLL file (Passfilt.dll) that lets
2633you enforce stronger password requirements for users. Passfilt.dll provides enhanced security
2634against "password guessing" or "dictionary attacks" by outside intruders.
2635
2636Passfilt.dll implements the following password policy:
2637? Passwords must be at least six (6) characters long. (The minimum password length can be
2638increased further by setting a higher value in the Password Policy for the domain).
2639? Passwords must contain characters from at least three (3) of the following four (4) classes:
2640Description Examples
2641English upper case letters A, B, C, ... Z
2642English lower case letters a, b, c, ... z
2643Westernized Arabic numerals 0, 1, 2, ... 9
2644Non-alphanumeric ("special characters") such as punctuation symbols
2645? Passwords may not contain your user name or any part of your full name.
2646
2647These requirements are hard-coded in the Passfilt.dll file and cannot be changed through the
2648user interface or registry. If you wish to raise or lower these requirements, you may write your
2649own .dll and implement it in the same fashion as the Microsoft version that is available with
2650Windows NT 4.0 Service Pack 2.
2651
2652To use Passfilt.Dll, the administrator must configure the password filter DLL in the system registry
2653on all domain controllers. This can be done as follows with the following registry key value:
2654
2655Hive: HKEY_LOCAL_MACHINE\SYSTEM
2656Key: System\CurrentControlSet\Control\LSA
2657Name: Notification Packages
2658Type: REG_MULTI_SZ
2659Value: Add string "PASSFILT" (do not remove existing ones).
2660
2661[6.1.9] Disabling LanManager Password Hash Support
2662 Completed Not implemented Not applicable
2663STATUS
2664
2665Windows NT supports the following two types of challenge/response authentication:
2666? LanManager (LM) challenge/response
2667? Windows NT challenge/response
2668
2669To allow access to servers that only support LM authentication, Windows NT clients currently
2670send both authentication types. Microsoft developed a patch that allows clients to be configured
2671to send only Windows NT authentication. This removes the use of LM challenge/response
2672messages from the network.
2673Applying this hot fix, configures the following registry key:
2674
2675Hive: HKEY_LOCAL_MACHINE\SYSTEM
2676Key: System\CurrentControlSet\Control\LSA
2677Name: LMCompatibilityLevel
2678Type: REG_DWORD
2679Value: 0,1,2 (Default 0)
2680
2681Setting the value to:
2682? 0 – Send both Windows NT and LM password forms.
2683? 1 – Send Windows NT and LM password forms only if the server requests it.
2684? 2 – Never send LM password form.
2685
2686If a Windows NT client selects level 2, it cannot connect to servers that support only LM
2687authentication, such as Windows 95 and Windows for Workgroups.
2688
2689For more complete information on this hot fix, please refer to Knowledge Base article number
2690Q147706.
2691
2692[6.2.0] Wiping the System Page File during clean system shutdown
2693 Completed Not implemented Not applicable
2694STATUS
2695
2696Virtual Memory support of Windows NT uses a system page file to swap pages from memory of
2697different processes onto disk when they are not being actively used. On a running system, this
2698page file is opened exclusively by the operating system and hence is well-protected. However,
2699systems that are configured to allow booting to other operating systems, may want to ensure that
2700system page file is wiped clean when Windows NT shuts down. This ensures that sensitive
2701information from process memory that may have made into the page file is not available to a
2702snooping user. This can be achieved by setting up the following key:
2703
2704Hive: HKEY_LOCAL_MACHINE\SYSTEM
2705Key: System\CurrentControlSet\Control\SessionManager\Memory Management
2706Name: ClearPageFileAtShutdown
2707Type: REG_DWORD
2708Value: 1
2709
2710Note that, this protection works only during a clean shutdown, therefore it is important that
2711untrusted users do not have ability to power off or reset the system manually.
2712
2713[6.2.1] Protecting the Registry
2714 Completed Not implemented Not applicable
2715STATUS
2716
2717All the initialization and configuration information used by Windows NT is stored in the registry.
2718Normally, the keys in the registry are changed indirectly, through the administrative tools such as
2719the Control Panel. This method is recommended. The registry can also be altered directly, with
2720the Registry Editor; some keys can be altered in no other way.
2721
2722The Registry Editor supports remote access to the Windows NT registry. To restrict network
2723access to the registry, use the Registry Editor to create the following registry key:
2724
2725Hive: HKEY_LOCAL_MACHINE
2726Key: \CurrentcontrolSet\Control\SecurePipeServers
2727Name: \winreg
2728
2729The security permissions set on this key define which users or groups can connect to the system
2730for remote registry access. The default Windows NT Workstation installation does not define this
2731key and does not restrict remote access to the registry. Windows NT Server permits only
2732administrators remote access to the registry.
2733
2734[6.2.2] Secure EventLog Viewing
2735 Completed Not implemented Not applicable
2736STATUS
2737
2738Default configuration allows guests and null log ons ability to view event logs (system, and
2739application logs). Security log is protected from guest access by default, it is viewable by users
2740who have "Manage Audit Logs" user right. The Event log services use the following key to
2741restrict guest access to these logs:
2742
2743Hive: HKEY_LOCAL_MACHINE
2744Key: \System\CurrentControlSet\Services\EventLog\[LogName]
2745Name: RestrictGuestAccess
2746Type REG_DWORD
2747Value: 1
2748
2749Set the value for each of the logs to 1. The change takes effect on next reboot. Needless to say
2750that you will have to change the security on this key to disallow everyone other than
2751Administrators and System any access because otherwise malicious users can reset these
2752values.
2753
2754[6.2.3] Secure Print Driver Installation
2755 Completed Not implemented Not applicable
2756STATUS
2757
2758Registry key AddPrinterDrivers under HKEY_LOCAL_MACHINE\System\CurrentControlSet\
2759Control\Print\Providers\LanMan Print Services\Servers, Key value AddPrinterDrivers
2760(REG_DWORD) is used to control who can add printer drivers using the print folder. This key
2761value should be set to 1 to enable the system spooler to restrict this operation to administrators
2762and print operators (on server) or power users (on workstation).
2763
2764Hive: HKEY_LOCAL_MACHINE
2765Key: System\CurrentcontrolSet\Control\Print\Providers\LanMan Print Services\Servers
2766Name: AddPrintDrivers
2767Type REG_DWORD
2768Value: 1
2769
2770[6.2.4] The Schedule Service (AT Command)
2771 Completed Not implemented Not applicable
2772STATUS
2773
2774The Schedule service (also known as the AT command) is used to schedule tasks to run
2775automatically at a preset time. Because the scheduled task is run in the context run by the
2776Schedule service (typically the operating system's context), this service should not be used in a
2777highly secure environment.
2778By default, only administrators can submit AT commands. To allow system operators to also
2779submit AT commands, use the Registry Editor to create or assign the following registry key value:
2780
2781Hive: HKEY_LOCAL_MACHINE\SYSTEM
2782Key: \CurrentControlSet\Control\Lsa
2783Name: Submit Control
2784Type: REG_DWORD
2785Value: 1
2786
2787There is no way to allow anyone else to submit AT commands. Protecting the registry as
2788explained earlier restricts direct modification of the registry key using the registry editor. Access
2789to the registry key HKEY_LOCAL_MACHINE\System\CurrentControlSet\ Services\Schedule
2790should also be restricted to only those users/groups (preferrably Administrators only) that are
2791allowed to submit jobs to the schedule service.
2792The changes will take effect the next time the computer is started. You might want to update the
2793Emergency Repair Disk to reflect these changes.
2794
2795[6.2.5] Secure File Sharing
2796 Completed Not implemented Not applicable
2797STATUS
2798
2799The native Windows NT file sharing service is provided using the SMB-based server and
2800redirector services. Even though only administrators can create shares, the default security
2801placed on the share allows Everyone full control access. These permissions are controlling
2802access to files on down level file systems like FAT which do not have security mechanisms built
2803in. Shares on NTFS enforce the security on the underlying directory it maps to and it is
2804recommended that proper security be put via NTFS and not via the file sharing service.
2805
2806Also note that the share information resides in the registry which also needs to be protected as
2807explained in a section earlier.
2808
2809? Service Pack 3 for Windows NT version 4.0 includes several enhancements to SMB based
2810file sharing protocol. These are:It supports mutual authentication to counter man-in-the-
2811middle attacks.
2812? It supports message authentication to prevent active message attacks.
2813
2814These are provided by incorporating message signing into SMB packets which are verified by
2815both server and client ends. There are registry key settings to enable SMB signatures on each
2816side. To ensure that SMB server responds to clients with message signing only, configure the
2817following key value:
2818
2819Hive: HKEY_LOCAL_MACHINE\SYSTEM
2820Key: System\CurrentControlSet\Services\LanManServer\Parameters
2821Name: RequireSecuritySignature
2822Type: REG_DWORD
2823Value: 1
2824
2825Setting this value ensures that the Server communicates with only those clients that are aware of
2826message signing. Note that this means that installations that have multiple versions of client
2827software, older versions will fail to connect to servers that have this key value configured.
2828
2829Similarly, security conscious clients can also decide to communicate with servers that support
2830message signing and no one else.
2831
2832Hive: HKEY_LOCAL_MACHINE\SYSTEM
2833Key: System\CurrentControlSet\Services\Rdr\Parameters
2834Name: RequireSecuritySignature
2835Type: REG_DWORD
2836Value: 1
2837
2838Note that setting this key value implies that the client will not be able to connect to servers which
2839do not have message signing support.
2840
2841Please refer to Knowledge Base article Q161372 for further details on SMB message signing
2842enhancements.
2843
2844Windows NT version 4.0 Service Pack 3 also includes another enhancement to SMB file sharing
2845protocol such that by default you are unable to connect to SMB servers (such as Samba or
2846Hewlett-Packard (HP) LM/X or LAN Manager for UNIX) with an unencrypted (plain text)
2847password. This protects from sending clear text forms of passwords over the wire. Please refer
2848to Knowledge base article Q166730 if you have any reasons to allow clients to send unencrypted
2849passwords over the wire.
2850
2851Additionally, customers may want to delete the administrative shares ($ shares) if they are not
2852needed on an installation. This can be accomplished using "net share" command. For example:
2853C:\> net share admin$ /d
2854
2855[6.2.6] Auditing
2856Auditing can inform you of actions that could pose a security risk and also identify the user
2857accounts from which audited actions were taken. Note that auditing only tells you what user
2858accounts were used for the audited events. If passwords are adequately protected, this in turn
2859indicates which user attempted the audited events. However, if a password has been stolen or if
2860actions were taken while a user was logged on but away from the computer, the action could
2861have been initiated by someone other than the person to whom the user account is assigned
2862When you establish an audit policy you'll need to weigh the cost (in disk space and CPU cycles)
2863of the various auditing options against the advantages of these options. You'll want to at least
2864audit failed log on attempts, attempts to access sensitive data, and changes to security settings.
2865Here are some common security threats and the type of auditing that can help track them:
2866
2867[6.2.7] Threat Action
2868Hacker-type break-in using random passwords Enable failure auditing for log on and log off
2869events.
2870Break-in using stolen password Enable success auditing for log on and log off events. The log
2871entries will not distinguish between the real users and the phony ones. What you are looking for
2872here is unusual activity on user accounts, such as log ons at odd hours or on days when you
2873would not expect any activity.
2874Misuse of administrative privileges by authorized users Enable success auditing for use of user
2875rights; for user and group management, for security policy changes; and for restart, shutdown,
2876and system events. (Note: Because of the high volume of events that would be recorded,
2877Windows NT does not normally audit the use of the Backup Files And Directories and the Restore
2878Files And Directories rights. Appendix B, "Security In a Software Development Environment,"
2879explains how to enable auditing of the use of these rights.)
2880Virus outbreak Enable success and failure write access auditing for program files such as files
2881with .exe and .dll extensions. Enable success and failure process tracking auditing. Run suspect
2882programs and examine the security log for unexpected attempts to modify program files or
2883creation of unexpected processes. Note that these auditing settings generate a large number of
2884event records during routine system use. You should use them only when you are actively
2885monitoring the system log.
2886Improper access to sensitive files Enable success and failure auditing for file- and object-
2887access events, and then use File Manager to enable success and failure auditing of read and
2888write access by suspect users or groups for sensitive files.
2889Improper access to printers Enable success and failure auditing for file- and object-access
2890events, and then use Print Manager to enable success and failure auditing of print access by
2891suspect users or groups for the printers.
2892
2893[6.2.8] Enabling System Auditing
2894 Completed Not implemented Not applicable
2895STATUS
2896
2897Enabling system auditing can inform you of actions that pose security risks and possibly detect
2898security breaches.
2899To activate security event logging, follow these steps:
29001. Log on as the administrator of the local workstation.
29012. Click the Start button, point to Programs, point to Administrative Tools, and then click User
2902Manager.
29033. On the Policies menu, click Audit.
29044. Click the Audit These Events option.
29055. Enable the options you want to use. The following options are available:
2906• Log on/Log off: Logs both local and remote resource logins.
2907• File and Object Access: File, directory, and printer access.
2908• Note: Files and folders must reside on an NTFS partition for security logging to be
2909enabled. Once the auditing of file and object access has been enabled, use Windows
2910NT Explorer to select auditing for individual files and folders.
2911• User and Group Management: Any user accounts or groups created, changed, or
2912deleted. Any user accounts that are renamed, disabled, or enabled. Any passwords set
2913or changed.
2914• Security Policy Changes: Any changes to user rights or audit policies.
2915• Restart, Shutdown, And System: Logs shutdowns and restarts for the local workstation.
2916• Process Tracking: Tracks program activation, handle duplication, indirect object
2917access, and process exit.
29186. Click the Success check box to enable logging for successful operations, and the Failure
2919check box to enable logging for unsuccessful operations.
29207.Click OK.
2921
2922Note that Auditing is a "detection" capability rather than "prevention" capability. It will help you
2923discover security breaches after they occur and therefore should always be consider in addition to
2924various preventive measures.
2925
2926[6.2.9] Auditing Base Objects
2927 Completed Not implemented Not applicable
2928STATUS
2929
2930To enable auditing on base system objects, add the following key value to the registry key
2931
2932Hive: HKEY_LOCAL_MACHINE\SYSTEM
2933Key: System\CurrentControlSet\Control\Lsa
2934Name: AuditBaseObjects
2935Type: REG_DWORD
2936Value: 1
2937
2938Note that simply setting this key does not start generating audits. The administrator will need to
2939turn auditing on for the "Object Access" category using User Manager. This registry key setting
2940tells Local Security Authority that base objects should be created with a default system audit
2941control list.
2942
2943[6.3.0] Auditing of Privileges
2944 Completed Not implemented Not applicable
2945STATUS
2946
2947Certain privileges in the system are not audited by default even when auditing on privilege use is
2948turned on. This is done to control the growth of audit logs. The privileges are:
29491. Bypass traverse checking (given to everyone).
29502. Debug programs (given only to administrators)
29513. Create a token object (given to no one)
29524. Replace process level token (given to no one)
29535. Generate Security Audits (given to no one)
29546. Backup files and directories (given to administrators and backup operators)
29557. Restore files and directories (given to administrators and backup operators)
2956
29571 is granted to everyone so is meaningless from auditing perspective. 2 is not used in a working
2958system and can be removed from administrators group. 3, 4 and 5 are not granted to any user or
2959group and are highly sensitive privileges and should not be granted to anyone. However 6 and 7
2960are used during normal system operations and are expected to be used. To enable auditing of
2961these privileges, add the following key value to the registry key
2962
2963Hive: HKEY_LOCAL_MACHINE\SYSTEM
2964Key: System\CurrentControlSet\Control\Lsa
2965Name: FullPrivilegeAuditing
2966Type: REG_BINARY
2967Value: 1
2968
2969Note that these privileges are not audited by default because backup and restore is a frequent
2970operation and this privilege is checked for every file and directory backed or restored, which can
2971lead to thousands of audits filling up the audit log in no time. Carefully consider turning on
2972auditing on these privilege uses.
2973
2974
2975
2976
2977[6.3.1] Protecting Files and Directories
2978 Completed Not implemented Not applicable
2979STATUS
2980
2981The NTFS file system provides more security features than the FAT system and should be used
2982whenever security is a concern. The only reason to use FAT is for the boot partition of an ARC-
2983compliant RISC system. A system partition using FAT can be secured in its entirety using the
2984Secure System Partition command on the Partition menu of the Disk Administrator utility.
2985
2986Among the files and directories to be protected are those that make up the operating system
2987software itself. The standard set of permissions on system files and directories provide a
2988reasonable degree of security without interfering with the computer's usability. For high-level
2989security installations, however, you might want to additionally set directory permissions to all
2990subdirectories and existing files, as shown in the following list, immediately after WindowsNT is
2991installed. Be sure to apply permissions to parent directories before applying permissions to
2992subdirectories.
2993
2994First apply the following using the ACL editor:
2995
2996Directory Permissions Complete
2997\WINNT and all subdirectories under it. Administrators: Full Control
2998CREATOR OWNER: Full Control
2999Everyone: Read
3000SYSTEM: Full Control
3001
3002Now, within the \WINNT tree, apply the following exceptions to the general security:
3003
3004Directory Permissions Complete
3005\WINNT\REPAIR Administrators: Full Control
3006\WINNT\SYSTEM32\CONFIG Administrators: Full Control
3007CREATOR OWNER: Full Control
3008Everyone: List
3009SYSTEM: Full Control
3010\WINNT\SYSTEM32\SPOOL Administrators: Full Control
3011CREATOR OWNER: Full Control
3012Everyone: Read
3013Power Users: Change
3014SYSTEM: Full Control
3015\WINNT\COOKIES
3016\WINNT\FORMS
3017\WINNT\HISTORY
3018\WINNT\OCCACHE
3019\WINNT\PROFILES
3020\WINNT\SENDTO
3021\WINNT\Temporary Internet Files Administrators: Full Control
3022CREATOR OWNER: Full Control
3023Everyone: Special Directory Access – Read, Write and Execute, Special File Access – None
3024System : Full Control
3025
3026Several critical operating system files exist in the root directory of the system partition on Intel
302780486 and Pentium-based systems. In high-security installations you might want to assign the
3028following permissions to these files:
3029
3030File C2-Level Permissions Complete
3031\Boot.ini, \Ntdetect.com, \Ntldr Administrators: Full Control
3032SYSTEM: Full Control
3033\Autoexec.bat, \Config.sys Everybody: Read
3034Administrators: Full Control
3035SYSTEM: Full Control
3036\TEMP directory Administrators: Full Control
3037SYSTEM: Full Control
3038CREATOR OWNER: Full Control
3039Everyone: Special Directory Access – Read, Write and Execute, Special File Access – None
3040
3041
3042To view these files in File Manager, choose the By File Type command from the View menu,
3043then select the Show Hidden/System Files check box in the By File Type dialog box.
3044
3045Note that the protections mentioned here are over and above those mentioned earlier in the
3046standard security level section, which included having only NTFS partitions (except the boot
3047partition in case of RISC machines). The FAT boot partition for RISC systems can be configured
3048using the Secure System Partition command on the Partition menu of the Disk Administrator
3049utility.
3050
3051It is also highly advisable that Administrators manually scan the permissions on various partitions
3052on the system and ensures that they are appropriately secured for various user accesses in their
3053environment.
3054
3055[6.3.2] Services and NetBIOS Access From Internet
3056For a stand-alone WEB or firewall server, consider the following guidelines
3057
3058The following services should NOT be started:
3059
3060Service Installed Not Installed
3061Alerter
3062ClipBook Server
3063Computer Browser
3064DHCP Client
3065Directory Replicator
3066Messenger
3067Net Logon
3068Network DDE
3069Network DDE DSDM
3070Plug and Play
3071Remote Procedure Call (RPC) Locator
3072Server
3073SNMP Trap Service
3074Spooler "unless print spooling is needed"
3075TCP/IP NetBIOS Helper
3076Telephony Service
3077Workstation
3078
3079The following services MUST be started:
3080
3081Service Installed Not Installed
3082EventLog
3083FTP Publishing Service (for FTP server)
3084Gopher Publishing Service (for Gopher server)
3085NT LM Security Support Provider
3086Remote Procedure Call (RPC) Service
3087SNMP
3088World Wide Web Publishing Service (for WWW server)
3089
3090The following services MAY be started if needed:
3091
3092Service Installed Not Installed
3093Schedule
3094UPS
3095
3096Disconnect the "NetBIOS Interface", the "Server" and the "Workstation" from the "WINS
3097Client(TCP/IP)"
3098
3099[6.3.3] Alerter and Messenger Services
3100
3101The Windows NT alerter and messenger services enable a user to send pop-up messages to
3102other users. A network administrator may consider this an unnecessary risk due to the fact that
3103these types of services have been known to be used in social engineering attacks. Some users
3104might actually respond to a request to change their password, create a share, or otherwise open
3105holes in the network. A side effect of running this service is that it causes the name of the current
3106user to be broadcast in the NetBIOS name table, which gives the attacker a valid user name to
3107use in brute force attempts.
3108
3109[6.3.4] Unbind Unnecessary Services from Your Internet Adapter Cards
3110
3111 Completed Not implemented Not applicable
3112STATUS
3113
3114Use the Bindings feature in the Network application in Control Panel to unbind any unnecessary
3115services from any network adapter cards connected to the Internet. For example, you might use
3116the Server service to copy new images and documents from computers in your internal network,
3117but you might not want remote users to have direct access to the Server service from the Internet.
3118
3119If you need to use the Server service on your private network, disable the Server service binding
3120to any network adapter cards connected to the Internet. You can use the Windows NT Server
3121service over the Internet; however, you should fully understand the security implications and
3122comply with Windows NT Server Licensing requirements issues.
3123
3124When you are using the Windows NT Server service you are using Microsoft networking (the
3125server message block [SMB] protocol rather than the HTTP protocol) and all Windows NT Server
3126Licensing requirements still apply. HTTP connections do not apply to Windows NT Server
3127licensing requirements.
3128
3129For Windows NT systems with direct Internet connectivity and have NetBios, there are two
3130configuration options:
3131• Configure the NT system on the Internet outside the corporate firewall. You can also
3132accomplish this by blocking ports 135, 137 and 138 on TCP and UDP protocols at the
3133firewall. This ensures that no NetBIOS traffic moves across the corporate firewall.
3134• Configure the protocol bindings between TCP/IP, NetBIOS, Server and Workstation
3135services using the network control panel. By removing the bindings between NetBIOS and
3136TCP/IP, the native file sharing services (using the Server and Workstation services) will not
3137be accessible via TCP/IP and hence the Internet. These and other NetBIOS services will
3138still be accessible via a local LAN-specific, non-routable protocol (ex: NetBEUI) if one is in
3139place. To accomplish this use the Network Control Panel applet. Select the Bindings Tab
3140and disable the NetBios bindings with TCP/IP protocol stack.
3141
3142A Windows NT system with direct Internet connectivity needs to be secured with respect to other
3143services besides NetBIOS access, specifically Internet Information Server
3144
3145NetBIOS over TCP/IP should normally be disabled for a firewall or web server. The following is a
3146list of the ports used by NBT.
3147? NetBIOS-ns 137/tcp NETBIOS Name Service
3148? NetBIOS-ns 137/udp NETBIOS Name Service
3149? NetBIOS-dgm 138/tcp NETBIOS Datagram Service
3150? NetBIOS-dgm 138/udp NETBIOS Datagram Service
3151? NetBIOS-ssn 139/tcp NETBIOS Session Service
3152? NetBIOS-ssn 139/udp NETBIOS Session Service
3153
3154[6.3.5] Enhanced Protection for Security Accounts Manager Database
3155
3156 Completed Not implemented Not applicable
3157STATUS
3158
3159The Windows NT Server 4.0 System Key hotfix (included in Service Pack 3) provides the
3160capability to use strong encryption techniques to increase protection of account password
3161information stored in the registry by the Security Account Manager (SAM). Windows NT Server
3162stores user account information, including a derivative of the user account password, in a secure
3163portion of the Registry protected by access control and an obfuscation function. The account
3164information in the Registry is only accessible to members of the Administrators group. Windows
3165NT Server, like other operating systems, allows privileged users who are administrators access to
3166all resources in the system. For installations that want enhanced security, strong encryption of
3167account password derivative information provides an additional level of security to prevent
3168Administrators from intentionally or unintentionally accessing password derivatives using Registry
3169programming interfaces.
3170
3171Please refer to Knowledge Base article Q143475 for more details on SysKey feature and how it
3172can be implemented on a Windows NT installation.
3173
3174[6.3.6] Disable Caching of Logon Credentials during interactive logon.
3175
3176 Completed Not implemented Not applicable
3177STATUS
3178
3179The default configuration of Windows NT caches the last logon credentials for a user who logged
3180on interactively to a system. This feature is provided for system availability reasons such as the
3181user's machine is disconnected or none of the domain controllers are online.
3182
3183Even though the credential cache is well protected, in a highly secure environments, customers
3184may want to disable this feature. This can be done by setting the following registry key:
3185
3186Hive: HKEY_LOCAL_MACHINE
3187Key: Software\Microsoft\Windows NT\CurrentVersion\Winlogon
3188Name: CachedLogonsCount
3189Type: REG_DWORD
3190Value: 0
3191
3192
3193[6.3.7] How to secure the %systemroot%\repair\sam._ file
3194
3195 Completed Not implemented Not applicable
3196STATUS
3197
3198By default, the SAM._ file and \repair directory has the following permissions;
3199
3200Administrators: Full Control
3201Everyone: Read
3202SYSTEM: Full Control
3203Power Users: Change
3204
32051.From within Explorer, highlight the SAM._ file, right click, choose properties, security,
3206permissions. Remove all privilege from this file.
32072.From a DOS prompt, execute the following;
3208
3209cacls %systemroot%\repair\sam._ /D Everyone
3210
3211This will deny the group Everyone permission to the file, ensuring that no other permission (i.e.
3212inherited permissions from a share) can override the file permission.
32133.Whenever you need to update your ERD, first execute the following from a DOS prompt;
3214
3215cacls %systemroot%\repair\sam._ /T /G Administrators:C
3216
3217This will grant Administrators change permission to update it during the ERD update.
3218
32194.Once the ERD has been updated, execute the following from a DOS prompt;
3220
3221cacls %systemroot%\repair\sam._ /E /R Administrators
3222
3223This will once again remove the permissions for Administrator
3224
3225How to enable auditing on password registry keys
3226
32271.First you have to make sure auditing is enabled. Start User Manager, Policies, Audit, and click
3228"Audit These Events".
32292.By default, Windows NT does not identify any users or groups to audit on any objects within the
3230system. Auditing can add performance overhead to your system depending on the available
3231resources, so care should be taken in determining what and whom to audit. For a full
3232description of auditing in Windows NT, I recommend the Microsoft Press book "Windows NT
32333.5 - Guidelines for Security, Audit, and Control", ISBN 1-55615-814-9. Despite its title it is
3234still the most comprehensive coverage of auditing that I have read. For the sake of this
3235example, we will simply check every Success and Failure checkbox.
32363.Close the dialog.
32374.Now for a little known trick. While logged on as Administrator, ensure that the Schedule service
3238is set to start up as the System account. Once set, start the Schedule service.
32395.Check the time, and then open a DOS prompt. At the DOS prompt, type in the following; at
324022:48 /interactive "regedt32.exe" where 22:48 gets replaced with the current time plus 1
3241minute (or 2 or whatever amount of time you think it will take you to type in the command).
32426.At the designated time, regedt32.exe will fire up and appear on your desktop. This incarnation
3243of regedt32.exe will be running in the security context of the user SYSTEM. As such, you will
3244be able to see the entire registry, every key within the SAM or Security trees. BE VERY
3245CAREFUL HERE. It is important to note that when running an application as SYSTEM, it
3246does so attempting to use null session for credentials. Null session support has been
3247disabled by default in all versions of Windows NT after 3.1, therefore any attempt to connect
3248to non-local resources as this security context will fail. An Administrator could enable null
3249session support through the registry, but such a configuration is strongly discouraged.
32507.All we want to do is enable auditing on the designated keys, nothing else. To this end, we
3251highlight the HKEY_LOCAL_MACHINE windows within regedt32. Next highlight the SAM
3252tree. Choose the Security menu item, then Auditing.
32538.Click on the Add button and choose Show Users.
32549.I'm going to recommend that you add the SYSTEM user, the group Domain Admins, and the
3255user Administrator. You want to cover any account which has the right to;
3256? "Take ownership of files or other objects"
3257? "Back up files and directories"
3258? "Manage auditing and security log"
3259? "Restore files and directories"
3260? "Add workstations to domain"
3261? "Replace a process level token"
326210.Click the Audit Permission on Existing Subkeys
326311.Next, click in the Success and Failure checkboxes for the following entries; - Query Value -
3264Set Value - Write DAC - Read Control
326512.Choose OK, and then Yes.
326613.Repeat the process for the Security tree.
326714.Close REGEDT32, and stop the Schedule service. You will want to set the Schedule service
3268to use a userID for startup which you create, rather than SYSTEM, in future. Take this
3269opportunity to create such a user and change the startup for Schedule.
3270
3271You will now have applied auditing to the entire SAM ensuring you'll be notified via the Event
3272Logger of any failed or successful access to your sensitive information by the only accounts
3273which have the ability to access such information. The issue of what to do when/if you discover
3274event notifications is beyond the scope of this document. Part of a good security policy is an
3275appropriate audit policy which would dictate how the event logs are reviewed, how the information
3276is verified, and what actions should be taken for each possible event.
3277
3278[6.3.8] TCP/IP Security in NT
3279
3280Note: This section is not meant to teach you the concepts behind the TCP/IP protocol. It is
3281assumed that a working knowledge of TCP/IP can be applied.
3282
3283 Windows NT has a built in TCP/IP security functionality that most people do not use or
3284know about. This functionality enables you to control the types of network traffic that can reach
3285your NT servers. Access can be allowed or denied based on specific TCP ports, UDP ports, and
3286IP protocols. This type of security is normally applied to servers connected directly to the internet,
3287which is not recommended.
3288 Do configure NT's built in TCP/IP security, follow these steps:
3289
3290 1 - Right click on Network Neighborhood and goto the properties option.
3291 2 - Select the Protocols tab, highlight TCP/IP and click on Properties.
3292 3 - Select the IP address tab of the TCP/IP properties screen.
3293 4 - Check the check box that reads "Enable Security".
3294 5 - Click on Configure
3295
3296 You should now be looking at the TCP/IP Security dialog, which has the following
3297options:
3298
3299 -Adapter: Specifies which of the installed network adapter cards you are configuring
3300 -TCP Ports
3301 -UDP Ports
3302 -IP Protocols
3303
3304 Within these settings, you would choose which ports and what access permissions you
3305would like to assign to those ports. The following list is a list of the well known TCP/IP ports. This
3306is not an in depth guide, just a quick reference (For more details, check RFC 1060).
3307
3308[6.3.9] Well known TCP/UDP Port numbers
3309
3310 Service Port Comments
3311
3312 TCP Ports
3313 echo 7/tcp
3314 discard 9/tcp sink null
3315 systat 11/tcp users
3316 daytime 13/tcp
3317 netstat 15/tcp
3318 qotd 17/tcp quote
3319 chargen 19/tcp ttytst source
3320 ftp-data 20/tcp
3321 ftp 21/tcp
3322 telnet 23/tcp
3323 smtp 25/tcp mail
3324 time 37/tcp timserver
3325 name 42/tcp nameserver
3326 whois 43/tcp nicname
3327 nameserver 53/tcp domain
3328 apts 57/tcp any private terminal service
3329 apfs 59/tcp any private file service
3330 rje 77/tcp netrjs
3331 finger 79/tcp
3332 http 80/tcp
3333 link 87/tcp ttylink
3334 supdup 95/tcp
3335 newacct 100/tcp [unauthorized use]
3336 hostnames 101/tcp hostname
3337 iso-tsap 102/tcp tsap
3338 x400 103/tcp
3339 x400-snd 104/tcp
3340 csnet-ns 105/tcp CSNET Name Service
3341 pop-2 109/tcp Post Office Protocol version 2
3342 pop-3 110/tcp Post Office Protocol version 3
3343 sunrpc 111/tcp
3344 auth 113/tcp authentication
3345 sftp 115/tcp
3346 uucp-path 117/tcp
3347 nntp 119/tcp usenet readnews untp
3348 ntp 123/tcp network time protocol
3349 statsrv 133/tcp
3350 profile 136/tcp
3351 NeWS 144/tcp news
3352 print-srv 170/tcp
3353 https 443/tcp Secure HTTP
3354 exec 512/tcp remote process execution;
3355 authentication performed using
3356 passwords and UNIX loppgin names
3357 login 513/tcp remote login a la telnet;
3358 automatic authentication performed
3359 based on priviledged port numbers
3360 and distributed data bases which
3361 identify "authentication domains"
3362 cmd 514/tcp like exec, but automatic
3363 authentication is performed as for
3364 login server
3365 printer 515/tcp spooler
3366 efs 520/tcp extended file name server
3367 tempo 526/tcp newdate
3368 courier 530/tcp rpc
3369 conference 531/tcp chat
3370 netnews 532/tcp readnews
3371 uucp 540/tcp uucpd
3372 klogin 543/tcp
3373 kshell 544/tcp krcmd
3374 dsf 555/tcp
3375 remotefs 556/tcp rfs server
3376 chshell 562/tcp chcmd
3377 meter 570/tcp demon
3378 pcserver 600/tcp Sun IPC server
3379 nqs 607/tcp nqs
3380 mdqs 666/tcp
3381 rfile 750/tcp
3382 pump 751/tcp
3383 qrh 752/tcp
3384 rrh 753/tcp
3385 tell 754/tcp send
3386 nlogin 758/tcp
3387 con 759/tcp
3388 ns 760/tcp
3389 rxe 761/tcp
3390 quotad 762/tcp
3391 cycleserv 763/tcp
3392 omserv 764/tcp
3393 webster 765/tcp
3394 phonebook 767/tcp phone
3395 vid 769/tcp
3396 rtip 771/tcp
3397 cycleserv2 772/tcp
3398 submit 773/tcp
3399 rpasswd 774/tcp
3400 entomb 775/tcp
3401 wpages 776/tcp
3402 wpgs 780/tcp
3403 mdbs 800/tcp
3404 device 801/tcp
3405 maitrd 997/tcp
3406 busboy 998/tcp
3407 garcon 999/tcp
3408 blackjack 1025/tcp network blackjack
3409 bbn-mmc 1347/tcp multi media conferencing
3410 bbn-mmx 1348/tcp multi media conferencing
3411 orasrv 1525/tcp oracle
3412 ingreslock 1524/tcp
3413 issd 1600/tcp
3414 nkd 1650/tcp
3415 dc 2001/tcp
3416 mailbox 2004/tcp
3417 berknet 2005/tcp
3418 invokator 2006/tcp
3419 dectalk 2007/tcp
3420 conf 2008/tcp
3421 news 2009/tcp
3422 search 2010/tcp
3423 raid-cc 2011/tcp raid
3424 ttyinfo 2012/tcp
3425 raid-am 2013/tcp
3426 troff 2014/tcp
3427 cypress 2015/tcp
3428 cypress-stat 2017/tcp
3429 terminaldb 2018/tcp
3430 whosockami 2019/tcp
3431 servexec 2021/tcp
3432 down 2022/tcp
3433 ellpack 2025/tcp
3434 shadowserver 2027/tcp
3435 submitserver 2028/tcp
3436 device2 2030/tcp
3437 blackboard 2032/tcp
3438 glogger 2033/tcp
3439 scoremgr 2034/tcp
3440 imsldoc 2035/tcp
3441 objectmanager 2038/tcp
3442 lam 2040/tcp
3443 interbase 2041/tcp
3444 isis 2042/tcp
3445 rimsl 2044/tcp
3446 dls 2047/tcp
3447 dls-monitor 2048/tcp
3448 shilp 2049/tcp
3449 NSWS 3049/tcp
3450 rfa 4672/tcp remote file access server
3451 complexmain 5000/tcp
3452 complexlink 5001/tcp
3453 padl2sim 5236/tcp
3454 man 9535/tcp
3455
3456
3457 UDP Ports
3458 echo 7/udp
3459 discard 9/udp sink null
3460 systat 11/udp users
3461 daytime 13/udp
3462 netstat 15/udp
3463 qotd 17/udp quote
3464 chargen 19/udp ttytst source
3465 time 37/udp timserver
3466 rlp 39/udp resource
3467 name 42/udp nameserver
3468 whois 43/udp nicname
3469 nameserver 53/udp domain
3470 bootps 67/udp bootp
3471 bootpc 68/udp
3472 tftp 69/udp
3473 sunrpc 111/udp
3474 erpc 121/udp
3475 ntp 123/udp
3476 statsrv 133/udp
3477 profile 136/udp
3478 snmp 161/udp
3479 snmp-trap 162/udp
3480 at-rtmp 201/udp
3481 at-nbp 202/udp
3482 at-3 203/udp
3483 at-echo 204/udp
3484 at-5 205/udp
3485 at-zis 206/udp
3486 at-7 207/udp
3487 at-8 208/udp
3488 biff 512/udp used by mail system to notify users
3489 of new mail received; currently
3490 receives messages only from
3491 processes on the same machine
3492 who 513/udp maintains data bases showing who's
3493 logged in to machines on a local
3494 net and the load average of the
3495 machine
3496 syslog 514/udp
3497 talk 517/udp like tenex link, but across
3498 machine - unfortunately, doesn't
3499 use link protocol (this is actually
3500 just a rendezvous port from which a
3501 tcp connection is established)
3502 ntalk 518/udp
3503 utime 519/udp unixtime
3504 router 520/udp local routing process (on site);
3505 uses variant of Xerox NS routing
3506 information protocol
3507 timed 525/udp timeserver
3508 netwall 533/udp for emergency broadcasts
3509 new-rwho 550/udp new-who
3510 rmonitor 560/udp rmonitord
3511 monitor 561/udp
3512 meter 571/udp udemon
3513 elcsd 704/udp errlog copy/server daemon
3514 loadav 750/udp
3515 vid 769/udp
3516 cadlock 770/udp
3517 notify 773/udp
3518 acmaint_dbd 774/udp
3519 acmaint_trnsd 775/udp
3520 wpages 776/udp
3521 puparp 998/udp
3522 applix 999/udp Applix ac
3523 puprouter 999/udp
3524 cadlock 1000/udp
3525 hermes 1248/udp
3526 wizard 2001/udp curry
3527 globe 2002/udp
3528 emce 2004/udp CCWS mm conf
3529 oracle 2005/udp
3530 raid-cc 2006/udp raid
3531 raid-am 2007/udp
3532 terminaldb 2008/udp
3533 whosockami 2009/udp
3534 pipe_server 2010/udp
3535 servserv 2011/udp
3536 raid-ac 2012/udp
3537 raid-cd 2013/udp
3538 raid-sf 2014/udp
3539 raid-cs 2015/udp
3540 bootserver 2016/udp
3541 bootclient 2017/udp
3542 rellpack 2018/udp
3543 about 2019/udp
3544 xinupagesrver 2020/udp
3545 xinuexpnsion1 2021/udp
3546 xinuexpnsion2 2022/udp
3547 xinuexpnsion3 2023/udp
3548 xinuexpnsion4 2024/udp
3549 xribs 2025/udp
3550 scrabble 2026/udp
3551 isis 2042/udp
3552 isis-bcast 2043/udp
3553 rimsl 2044/udp
3554 cdfunc 2045/udp
3555 sdfunc 2046/udp
3556 dls 2047/udp
3557 shilp 2049/udp
3558 rmontor_scure 5145/udp
3559 xdsxdm 6558/udp
3560 isode-dua 17007/udp
3561
3562[7.0.0] Preface to Microsoft Proxy Server
3563This section was not made for people who have been working with Microsoft Proxy Server since
3564its beta (catapult) days. It is made for individuals who are curious about the product and security
3565professionals that are curious as to what Microsoft Proxy Server has to offer. This section is also
3566being written for individuals have a general idea of what a Proxy Server does, but wants to know
3567more. This section goes into discussion of Proxy Server Features and Architecture, Access
3568Control, Encryption, and Firewall Strategies (which I have been getting a lot of requests for).
3569
3570The second part of the documentation goes into Firewall types and strategies, so if that's the
3571reason you downloaded the documentation, go straight to page 8 I believe.
3572
3573[7.0.1] What is Microsoft Proxy Server?
3574Microsoft Proxy Server is a "firewall" and cache server. It provides additional Internet security and
3575can improve network response issues depending on its configuration. The reason I put the word
3576firewall in quotes is because Proxy Server should not be considered as a stand-alone solution to
3577a firewall need. When you are done reading this document, you will have an advanced
3578understanding of the Proxy Server product and also understand firewall techniques and
3579topologies.
3580
3581Proxy Server can be used as an inexpensive means to connect an entire business through only
3582one valid IP address. It can also be used to allow more secure inbound connections to your
3583internal network from the Internet. By using Proxy Server, you are able to better secure your
3584network against intrusion. It can be configured to allow your entire internal private network to
3585access resources on the Internet, at the same time blocking any inbound access.
3586
3587Proxy Server can also be used to enhance the performance of your network by using advanced
3588caching techniques. The can be configured to save local copies of requested items from the
3589Internet. The next time that item is requested, it can be retrieved from the cache without having to
3590connect to the original source. This can save an enormous amount of time and network
3591bandwidth.
3592
3593Unlike Proxy Server 1.0, Proxy Server 2.0 includes packet filtering and many other features that
3594we will be discussing.
3595
3596Proxy Server provides it functionality by using three services:
3597
3598? Web Proxy: The web proxy service supports HTTP, FTP, and Gopher for TCP/IP Clients.
3599? WinSock Proxy: The Winsock proxy supports Windows Sockets client applications. It
3600provides support for clients running either TCP/IP or IPX/SPX. This allows for networks that
3601may be running more of a Novell environment to still take advantage of Proxy Server.
3602? SOCKS Proxy: The SOCKS Proxy is a cross-platform service that allows for secure
3603communication in a client/server capacity. This service supports SOCKS version 4.3a and
3604allows users access to the Internet by means of Proxy Server. SOCKS extends the
3605functionality provided by the WinSock service to non-Windows platforms such as Unix or
3606Macintosh.
3607
3608[7.0.2] Proxy Servers Security Features
3609
3610In conjunction with other products, Proxy Server can provide firewall level security to prevent
3611access to your internal network.
3612? Single Contact Point: A Proxy Server will have two network interfaces. One of these network
3613interfaces will be connected to the external (or "untrusted") network, the other interface will be
3614connected to your internal (or "trusted") network. This will better secure your LAN from
3615potential intruders.
3616? Protection of internal IP infrastructure: When IP forwarding is disabled on the Proxy Server,
3617the only IP address that will be visible to the external environment will be the IP address of
3618the Proxy Server. This helps in preventing intruders from finding other potential targets on
3619your network.
3620? Packet Layer Filtering: Proxy Server adds dynamic packet filtering to its list of features. With
3621this feature, you can block or enable reception of certain packet types. This enables you to
3622have a tremendous amount of control over your network security.
3623
3624[7.0.3] Beneficial Features of Proxy
3625
3626? IIS and NT Integration: Proxy Server integrates with Windows NT and Internet Information
3627Server tighter than any other package available on the market. Proxy Server actually uses
3628the same administrative interface used by Internet Information Server.
3629? Bandwidth Utilization: Proxy Server allows all clients in your network to share the same link to
3630the external network. In conjunction with Internet Information Server, you can set aside a
3631certain portion of your bandwidth for use by your webserver services.
3632? Caching Mechanisms: Proxy Server supports both active and passive caching. These
3633concepts will be explained in better detail further into the document.
3634? Support for Web Publishing: Proxy Server uses a process known as reverse proxy to provide
3635security while simultaneously allowing your company to publish on the Internet. Using
3636another method known as reverse hosting, you can also support virtual servers through
3637Proxy.
3638
3639[7.0.4] Hardware and Software Requirements
3640
3641Microsoft suggests the following minimum hardware requirements.
3642
3643? Intel 486 or higher. RISC support is also available.
3644? 24 MB Ram for Intel chips 32 MB Ram for RISC.
3645? 10 MB Diskspace needed for installation. 100 MB + .5 MB per client for Cache space.
3646? 2 Network interfaces (Adapters, Dial-Up, etc)
3647
3648Following is the suggested minimum software requirements.
3649
3650? Windows NT server 4.0
3651? Internet Information Server 2.0
3652? Service Pack 3
3653? TCP/IP
3654
3655It is highly recommended that it be installed on an NTFS partition. If a NTFS partition is not used,
3656not only are you losing NTFS's advanced security features, but also the caching mechanisms of
3657Proxy Server will not work.
3658
3659It is also recommended that your two network interfaces be configured prior to installation. On
3660interface configured to the external network, and one configured for the internal network. (Note:
3661When configuring your TCP/IP settings, DO NOT configure a default gateway entry for your
3662internal network interface.)
3663
3664? Be sure that "Enable IP Forwarding" is not checked in your TCP/IP settings. This could
3665seriously compromise your internal security.
3666
3667[7.0.5] What is the LAT?
3668
3669This is probably one of the most common questions I am asked as a security professional. The
3670LAT, or Local Address Table, is a series of IP address pairs that define your internal network.
3671Each pair defines a range of IP addresses or a single pair.
3672
3673That LAT is generated upon installation of Proxy Server. It defines the internal IP addresses.
3674Proxy Server uses the Windows NT Routing Table to auto-generate the LAT. It is possible that
3675the when the LAT is auto-generated, that errors in the LATs construction will be found. You
3676should always manually comb through the LAT and check for errors. It is not uncommon to find
3677external IP addresses in the LAT, or entire subnets of your internal IP addresses will not appear
3678on the LAT. It is generally a good idea to have all of your internal IP addresses in the LAT.
3679
3680? NO EXTERNAL IP ADDRESSES SHOULD APPEAR IN YOUR LAT.
3681
3682Upon installing the Proxy Server client software, it adds a file named msplat.txt into the \Mspclnt
3683directory. The msplat.txt file contains the LAT. This file is regularly updated from the server to
3684ensure that the LAT the client is using is current.
3685
3686[7.0.6] What is the LAT used for?
3687
3688Every time a client attempts to use a Winsock application to establish a connection, the LAT is
3689referenced to determine if the IP address the client is attempting to reach is internal or external. If
3690the IP address is internal, Proxy Server is bypassed and the connection is made directly. If the IP
3691address the client is attempting to connect to DOES NOT appear in the LAT, it is determined that
3692the IP address is remote and the connection is made through Proxy Server. By knowing this
3693information, someone on your internal network could easily edit his or her LAT table to bypass
3694Proxy Server.
3695
3696Some Administrators may not see this as a problem because the LAT is regularly updated from
3697the server, so any changes the user made to his or her LAT will be overwritten. However, if the
3698user saves their LAT with the filename Locallat.txt, the client machine will reference both the
3699msplat.txt and the locallat.txt to determine if an IP address is local or remote. So, by using the
3700locallat.txt method, a user can, in theory, permanently bypass Proxy Server. The locallat.txt file is
3701never overwritten unless the user does so manually.
3702
3703[7.0.7] What changes are made when Proxy Server is installed?
3704
3705Server side changes:
3706
3707? The Web Proxy, Winsock Proxy, and SOCKS Proxy services are installed and management
3708items are added into the Internet Service Manager.
3709? An HTML version of the documentation is added into the %systemroot%\help\proxy\
3710directory.
3711? A cache area is created on an NTFS volume.
3712? The LAT table is constructed.
3713? Proxy Server Performance Monitor counters are added.
3714? Client installation and config files are added to the Msp\Clients folder. This folder is shared as
3715Mspclnt and by default has the permissions set to Read for Everyone.
3716
3717Client side changes:
3718? The LAT (msplat.txt) file is copied to the clients local hard drive.
3719? A WSP Client icon is added to control panel on Win3.X, Win95 and WinNT clients.
3720? A Microsoft Proxy Client Program Group is added
3721? The winsock.dll file is replace with Remote WinSock for Proxy. The old winsock file is
3722renamed winsock.dlx.
3723? Mspclnt.ini file is copied to the client machine.
3724
3725[7.0.8] Proxy Server Architecture
3726
3727To understand the architecture of Microsoft Proxy Server, you must first have a basic grasp of
3728how Proxy works for outbound client requests. Here is a simple example:
3729
3730Joe opens his browser to visit his favorite news site on the net. He types in the sites IP address
3731which he has memorized because his visits often, instead of doing his job. The client compares
3732the IP address Joe entered to the LAT table. Because the IP address is not found on the LAT, it is
3733considered external. Since the client has determined that the IP address is external, it knows it
3734must process the request through Proxy Server. The client hands Joe's request to Proxy Server.
3735Proxy Server then checks the IP address against the access control applied by the Administrator.
3736The Administrator has the ability to stop internal employees from visiting certain sites. Since Joe's
3737request is not on the forbidden list applied by the Administrator, Proxy Server executes the
3738request. Proxy contacts the website and requests the document Joe wanted. After Proxy server
3739has received the information it requested, it stored a copy in its cache for later use and hands the
3740request to the client machine. The website pops-up on Joe's browser.
3741
3742[7.0.9] Proxy Server Services: An Introduction
3743
3744? WebProxy: Web Proxy normally functions with both clients and servers. As a server, it
3745receives HTTP requests from internal network clients. As a client, it responds to internal
3746network clients' requests by issuing their requests to a server on the Internet. The interface
3747between the client and server components of the Web Proxy service provides chances to add
3748value to the connections it services. By performing advanced security checks, the Web Proxy
3749does more than relay requests between an internal client and a server on the Internet. The
3750WebProxy service is an extensions of Internet Information Server 3.0. It consists of two
3751following components: The Proxy Server ISAPI Filter and the Proxy Server ISAPI Application.
3752The Web Proxy service is implemented as a DLL (dynamic link library) that uses ISAPI
3753(Internet Server Application Programming Interface) and therefore runs within the IIS WWW
3754process. The WWW Service must installed and running in order for proxy requests to be
3755processed.
3756? WinSock Proxy: WinSock Proxy provides proxy services for windows sockets applications.
3757WinSock Proxy allows winsock applications to function on a LAN and to operate as if it is
3758directly connected to the Internet. The client app uses Windows Sockets APIs to
3759communicate with another application running on an Internet computer. WinSock Proxy
3760intercepts the windows sockets call and establishes a communication path from the internal
3761application to the Internet application through the proxy server. The process is totally
3762transparent to the client. The WinSock Proxy consists of a service running on Proxy Server
3763and a DLL installed on each client. The DLL it relies on is the Remote Winsock DLL that
3764replaced the normal winsock.dll. WinSock Proxy uses a control channel between the client
3765and the server to manage the ability of Windows Sockets messages to be used remotely. The
3766control channel is set up when the WinSock Proxy client DLL is first loaded, and it uses the
3767connectionless UDP protocol. The Winsock Proxy client and the WinSock Proxy service use
3768a simple ack protocol to add reliability to the control channel. The control channel uses UDP
3769port 1745 on the proxy server and client computers.
3770? SOCKS Proxy: Proxy Server supports SOCKS Version 4.3a. Almost all SOCKS V4.0 client
3771applications can run remotely through SOCKS Proxy. SOCKS is a protocol that functions as
3772a proxy. It enables hosts on one side of a SOCKS server to gain full access to hosts on the
3773other side of a SOCKS server, without requiring direct IP access. (To learn more about
3774SOCKS, visit http://www.socks.nec.com/index.html).
3775
3776[7.1.0] Understanding components
3777
3778This area will attempt to better define to the components of the architecture that we have used,
3779but may not have defined.
3780
3781[7.1.1] ISAPI Filter
3782
3783The ISAPI Filter interface is one of the components of the web proxy service. The interface
3784provides an extension that the Web server calls whenever it receives an HTTP request.
3785
3786An ISAPI Filter is called for every request, regardless of the identity of the resource requested in
3787the URL. An ISAPI filter can monitor, log, modify, redirect and authenticate all requests that are
3788received by the Web server. The Web service can call an ISAPI filter DLL's entry point at various
3789times in the processing of a request or response. The Proxy Server ISAPI filter is contained in the
3790w3proxy.dll file. This filter examines each request to determine if the request is a standard HTTP
3791request or not.
3792
3793[7.1.2] ISAPI Application
3794
3795The ISAPI Application is the second of the two web proxy components. ISAPI applications can
3796create dynamic HTML and integrate the web with other service applications like databases.
3797
3798Unlike ISAPI Filters, an ISAPI Application is invoked for a request only if the request references
3799that specific application. An ISAPI Application does not initiate a new process for every request.
3800The ISAPI Application is also contained in the w3proxy.dll file.
3801
3802[7.1.3] Proxy Servers Caching Mechanism
3803
3804Microsoft Proxy Server handles caching in two different ways, Passive and Active caching.
3805
3806? Passive Caching: Passive caching is the basic mode of caching. Proxy Server interposes
3807itself between a client and an internal or external Web site and then intercepts client
3808requests. Before forwarding the request on to the Web server, Proxy Server checks to see if
3809it can satisfy the request from its cache. Normally, in passive caching, Proxy Server places a
3810copy of retrieved objects in the cache and associates a TTL (time-to-live) with that object.
3811During this TTL, all requests for that object are satisfied from the cache. When the TTL is
3812expired, the next client request for that object will prompt Proxy Server to retrieve a fresh
3813copy from the web. If the disk space for the cache is too full to hold new data, Proxy Server
3814removes older objects from the cache using a formula based on age, popularity, and size.
3815? Active Caching: Active Caching works with passive caching to optimize the client
3816performance by increasing the likelihood that a popular will be available in cache, and up to
3817date. Active caching changes the passive caching mechanism by having the Proxy Server
3818automatically generate requests for a set of objects. The objects that are chosen are based
3819on popularity, TTL, and Server Load.
3820
3821[7.1.4] Windows Sockets
3822
3823Windows Sockets is the mechanism for communication between applications running on the
3824same computer or those running on different computers which are connected to a LAN or WAN.
3825Windows Sockets defines a set of standard API's that an application uses to communicate with
3826one or more other applications, usually across a network. Windows Sockets supports initiating an
3827outbound connection, accepting inbound connections, sending and receiving data on those
3828connections, and terminating a session.
3829
3830Windows socket is a port of the Berkeley Sockets API that existed on Unix, with extensions for
3831integration into the Win16 and Win32 application environments. Windows Sockets also includes
3832support for other transports such as IPX/SPX and NetBEUI.
3833
3834Windows Sockets supports point-to-point connection-oriented communications and point-to-point
3835or multipoint connectionless communications when using TCP/IP. Windows Socket
3836communication channels are represented by data structures called sockets. A socket is identified
3837by an address and a port, for example;
3838
3839131.107.2.200:80
3840
3841[7.1.5] Access Control Using Proxy Server
3842
3843[7.1.6] Controlling Access by Internet Service
3844
3845Proxy Server can be configured to provide or restrict access based on Service type. FTP, HTTP,
3846Gopher, and Secure (SSL) are all individually configurable.
3847
3848[7.1.7] Controlling Access by IP, Subnet, or Domain
3849
3850Proxy allows an administrator to control access based on IP Address, Subnet or Domain. This is
3851done by enabling filtering and specifying the appropriate parameters. When configuring this
3852security, you need to decide if you want to grant or deny access to an IP address, subnet, or
3853domain. By configuring Proxy Server correctly, you can also set it up to use the internet as your
3854corporate WAN.
3855
3856[7.1.8] Controlling Access by Port
3857
3858If you are using the WinSock Proxy service, you can control access to the internet by specifying
3859which port is used by TCP and UDP. You can also grant or deny, activate or disable certain ports
3860based on your needs.
3861
3862[7.1.9] Controlling Access by Packet Type
3863
3864Proxy Server can control access of external packets into the internal network by enabling packet
3865filtering on the external interface. Packet filtering intercepts and evaluates packets from the
3866Internet before they reach the proxy server. You can configure packet filtering to accept or deny
3867specific packet types, datagrams, or packet fragments that can pass through Proxy Server. In
3868addition, you can block packets originating from a specific Internet host.
3869
3870The packet filtering provided by Proxy Server is available in two forms, Dynamic and Static.
3871
3872Dynamic packet filtering allows for designed ports to automatically open for transmission, receive,
3873or both. Ports are then closed immediately after connection has been terminated, thereby
3874minimizing the number of open ports and the duration of time that a port is open.
3875
3876Static packet filtering allows manual configuration of which packets are and are not allowed.
3877
3878By default, the following Packet settings are enabled on Proxy Server (by default, ALL packet
3879types are blocked except the ones listed below, known as Exceptions):
3880
3881Inbound ICMP ECHO (Ping)
3882Inbound ICMP RESPONSE (Ping)
3883Inbound ICMP SOURCE QUENCH
3884Inbound ICMP TIMEOUT
3885Inbound ICMP UNREACHABLE
3886Outbound ICMP ANY
3887Inbound TCP HTTP
3888In/Outbound UDP ANY (dns)
3889
3890[7.2.0] Logging and Event Alerts
3891
3892Events that could affect your system may be monitored, and, if they occur, alerts can be
3893generated. The items listed below are events that will generate alerts:
3894
3895Rejected Packets: Watches external adapter for dropped IP packets.
3896Protocol Violations: Watches for packets that do not follow the allowed protocol structure.
3897Disk Full: Watches for failures caused by a full disk.
3898
3899When any of the events above occur, an alert is sent to the system log in the NT Event Viewer, or
3900can be configured to e-mail a pre-defined person.
3901
3902When the system logs information concerning Access Control, it does so to a log file stored in the
3903%systemroot%/system32/msplogs/ directory. The log file itself is named Pfyymmdd.log (Where
3904yy=Current year / mm= Current Month / dd= Current day).
3905
3906The Packet log records information related to the following areas:
3907
3908Service Information (Time of Service, Date and Time)
3909Remote Information (The Source IP Address of a possible Intruder, along with port and protocol
3910used)
3911Local Information (Destination IP Address and port)
3912Filter Information (Action taken and what interface (network adapter) issued the action)
3913Packet Information (Raw IP Header in Hex and Raw IP Packet in Hex)
3914
3915[7.2.1] Encryption Issues
3916
3917Proxy Server can take full advantage of the authentication and security features of Internet
3918Information Server and SSL tunneling.
3919
3920SSL supports data encryption and server authentication. All data sent to and from the client using
3921SSL is encrypted. If HTTP basic authentication is used in conjunction with SSL, the user name
3922and password are transmitted after the client's SSL support encrypts them.
3923
3924If your are wanting to take advantage of PPTP to provide additional Demitriibility and security for your
3925clients, you can configure Proxy Server to allow these packets (GRE) to pass through.
3926
3927[7.2.2] Other Benefits of Proxy Server
3928
3929[7.2.3] RAS
3930
3931Proxy Server can take full advantage of Windows NT Remote Access Service (RAS). Proxy can
3932be configured to dial on demand when an internal client makes a request that must be satisfied
3933from the external network. The RAS feature can be configured to only allow connectivity during
3934certain hours. The Dial-Up Network Scripting tool can aslo be used to automate certain process
3935using Proxy Server and RAS. For company's who have a standard constant connection (ISDN,
3936T1, T3) to the Internet, the RAS ability provided by Proxy Server can be used as a back-up
3937should your constant connection fail.
3938
3939[7.2.4] IPX/SPX
3940
3941Microsoft Proxy Server was developed with support for Internet Packet Exchange/Sequenced
3942Packet Exchange or IPX/SPX. IPX/SPX is a transport protocol group somewhat similar to TCP/IP.
3943
3944There are many situations when a client computer may have both IPX/SPX and TCP/IP protocols
3945installed although the company's internal network may only use IPX/SPX. Simply disabling
3946aTCP/IP while on the LAN will not get the IPX/SPX component of the Proxy client software
3947working. You will need to go into Control Panel, open the Wsp Client icon and check the box that
3948reads "Force IPX/SPX protocol". This must be done because even though the TCP/IP protocol
3949was disabled, the WinSock Proxy Client still detects its presence and will attempt to create a
3950standard IP socket. By enabling the "Force IPX/SPX Protocol" option, this problem should
3951disappear.
3952
3953[7.2.5] Firewall Strategies
3954
3955A firewall is a system that enforces access control policies. The enforcement is done between an
3956internal, or "trusted" network and an external, or "untrusted" network. The firewall can be as
3957advanced as your standards require. Firewalls are commonly used to shield internal networks
3958from unauthorized access via the Internet or other external network.
3959
3960[7.2.6] Logical Construction
3961
3962The single basic function of a firewall is to block unauthorized traffic between a trusted system
3963and an untrusted system. This process is normally referred to as Filtering. Filtering can be viewed
3964as either permitting or denying traffic access to a network.
3965
3966Firewalls know what traffic to block because they are configured with the proper information. This
3967information is known as an Access Control Policy. The proper approach to an access control
3968policy will depend on the goals of the network security policy and the network administrator.
3969
3970[7.2.7] Exploring Firewall Types
3971
3972In the origins of firewalls, there were two types. These two types have now grown and overlapped
3973each other to the point where distinction is hard. We will explore the differences between these
3974two types and discuss Firewall building topologies.
3975
3976Network Level Firewalls
3977
3978Network level firewalls operate at the IP packet level. Most of these have a network interface to
3979the trusted network and an interface to the untrusted network. They filter by examining and
3980comparing packets to their access control policies or ACL's.
3981
3982Network level firewalls filter traffic based on any combination of Source and Destination IP, TCP
3983Port assignment and Packet Type. Network Level firewalls are normally specialized IP routers.
3984They are fast and efficient and are transparent to network operations. Todays network level
3985firewalls have become more and more complex. They can hold internal information about the
3986packets passing through them, including the contents of some of the data. We will be discussing
3987the following types of network level firewalls:
3988
3989? Bastion Host
3990? Screened Host
3991? Screened Subnet
3992
3993Bastion Host Firewall
3994
3995Bastion host are probably one of the most common types of firewalls. The term bastion refers to
3996the old castle structures used in Europe, mainly for draw bridges.
3997
3998The Bastion host is a computer with at east one interface to the trusted network and one to the
3999untrusted network. When access is granted to a host from the untrusted network by the bastion
4000host, all traffic from that host is allowed to pass unbothered.
4001In a physical layout, bastion hosts normally stand directly between the inside and outside
4002networks, with no other intervention. They are normally used as part of a larger more
4003sophisticated firewall.
4004
4005The disadvantages to a bastion host are:
4006
4007? After an Intruder has gained access, he has direct access to the entire network.
4008? Protection is not advanced enough for most network applications.
4009
4010Screened Host Firewall
4011
4012A more sophisticated network level firewall is the screened host firewall. This firewall uses a
4013router with at least on connection to trusted network and one connection to a bastion host. The
4014router serves as a preliminary screen for the bastion host. The screening router sends all IP traffic
4015to the bastion host after it filters the packets. The router is set up with filter rules. These rules
4016dictate which IP addresses are allowed to connect, and which ones are denied access. All other
4017packet scrutiny is done by the bastion host. The router decreases the amount of traffic sent to the
4018bastion host and simplifies the bastions filtering algorithms.
4019
4020The physical layout of a Screened Host is a router with one connection to the outside network,
4021and the other connection with a bastion host. The bastion host has one connection with the router
4022and one connection with the inside network.
4023
4024Disadvantages to the Screened Host are:
4025
4026? The single screen host can become a traffic bottleneck
4027? If the host system goes down, the entire gateway is down.
4028
4029Screened Subnet Firewalls
4030
4031A screened subnet uses on or more addition routers and on more additional bastion hosts. In a
4032screened subnet, access to and from the inside network is secured by using a group of screened
4033bastion host computers. Each of the bastion hosts acts as a drawbridge to the network.
4034
4035The physical layout of a Screened subnet is somewhat more difficult, but the result is a more
4036secure, robust environment. Normally, there is a router with one connection to the outside
4037network and the other connection to a bastion host. The bastion host has one connection to the
4038outer most router and one connection to another bastion host, with an addressable network in the
4039middle. The inner most bastion host has one connection to the outer most bastion and another
4040connection to an inside router. The inside router has one connection to the inner bastion host and
4041the other connection to the inside network. The result of this configuration is the security
4042components are normally never bogged down with traffic and all internal IP addresses are hidden
4043from the outside, preventing someone from "mapping" your internal network.
4044
4045Disadvantages to using this type of firewall are:
4046
4047? The can be two or three times more expensive than other types of firewalls
4048? Implementation must be done by some type of security professional, as these types of
4049firewalls are not for the un-initiated.
4050
4051Application Level Firewalls
4052
4053 Application level firewalls are hosts running proxy server software located between the protected
4054network and the outside network. Keep in mind that even though Microsofts product is called
4055Proxy Server 2.0, it is actually a stand alone Bastion Host type of system. Microsoft Proxy Server
4056can also, single-handedly, disguise your internal network to prevent mapping. Microsoft Proxy
4057Server 1.0 did not have many of the advanced features presented in version 2.0. The 1.0 version
4058can definitely be called a true proxy server, while the 2.0 version is more of a firewall.
4059
4060Viewed from the client side, a proxy server is an application that services network resource
4061requests by pretending to be the target source. Viewed from the network resource side, the proxy
4062server is accessing network resources by pretending to be the client. Application level firewalls
4063also do not allow traffic to pass directly between to the two networks. They are also able to use
4064elaborate logging and auditing features. They tend to provide more detailed audit reports, but
4065generally, as stand alone security unites, do not perform that well. Remember that an Application
4066level firewall is software running on a machine, and if that machine can be attacked effective and
4067crashed, in effect, youre crashing the firewall.
4068
4069You may wish to use an application level firewall in conjunction with network level firewalls, as
4070they provide the best all around security.
4071
4072[7.2.3] NT Security Twigs and Ends
4073
4074Lets jump right in. For those of you who are not riggers (architecture/network media specialists)
4075let me begin by saying that NT as an operating system is fairly safe and secure. Now you may
4076think to yourself that it isn’t, but think about all the Unix related security holes you know of, a ton
4077huh? Anyhow, as with any operating system, NT has holes, lets see what we can learn about
4078these holes, shall we?
4079
4080 First things first, NT does not support alot of the normal TCP/IP functions that youre used to. NT
4081does not normally support NFS, SunRPC, NIS, r* commands, Telnet, and some other obscure
4082ones.
4083
4084 In order for NT to allow for various system services to be performed on a remote computer, it
4085uses RPC, remote procedure calls. Please do not confuse this with SunRPC. You can run
4086NT/RPC's over a NetBIOS/SMB session or you can piggie back it directly off of TCP/IP (or other
4087transport protocol, perhaps NWLink IPX/SPX). Unfortunately we dont have any good
4088documentation on what inherent services NT provides through native RPC. Complex server type
4089programs (Like Exchange) provide their own RPC services in addition to the ones NT provides as
4090an operating system --(TCP Port 135 is used as a port-mapper port, we also know that if too
4091much information is fed through port 135, you can crash an NT box.). Some client software must
4092access TCP port 135 before accessing the RPC service itself (hint, hint). Keep in mind that TCP
4093port 135 can be blocked. Bummer, eh?
4094 One problem among the Hacker community is that most hackers dont like to investigate new
4095avenues, or explore new methods. They will take the easy way out, using a method thats already
4096been documented by someone else. So what if they come across a system that has patched that
4097security problem? Will todays hacker try to find a new way in? Nope... most of the slackers I know
4098will give up. It is for this reason that alot of the members in the community have never heard of
4099SMBs, because its a session level protocol that is not a Unix standard (although there is
4100something somewhat like SMBs for Unix, known as Samba). SMBs are used by Windows 3.X,
4101Win95, WintNT and OS/2. The one thing to remember about SMBs is that it allows for remote
4102access to shared directories, the registry, and other system services. Which makes it important in
4103our line of, uuuhh, work. As stated above, unfortunately, there is no good documentation of the
4104services that use SMBs.
4105
4106 Now, a couple of Key Points:
4107 SMBs are used by:
4108 -Win 3.X
4109 -Win 95
4110 -Win NT
4111 -OS/2
4112 SMBs allow for remote access to:
4113 -Shared directories
4114 -The Registry
4115 -Other system services
4116
4117 You will find that by default all accounts in NT have complete SMB functionality. This includes
4118the Guest account. (In WinNT 3.51, the guest is auto created and active, in WinNT 4.0, the guest
4119account is auto created but is not active) Now, 2 things to remember: When it comes to login
4120attempt failures, the administrator account IS NEVER locked out after a certain number of login
4121attempts (this rule ALWAYS applies), also by default, when windows NT is installed, NONE of the
4122accounts have fail login attempt lock out. Also, in order for SMB to work, UDP/TCP ports
4123137,138,139 (NetBIOS over TCP) must be open.
4124
4125---A word about Remote registry alteration: By default the Everyone group in NT has write access
4126to much of the registry. In NT 3.51, this was a major issue due to the remote registry access
4127feature of RegEdit. Any user could manipulate the registry on any server or workstation on which
4128his account (or the guest account) was enabled. WindowsNT fixed the problem with this registry
4129key:
4130
4131HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipesServers\winreg
4132
4133Now, true, remote registry editing is not allowed in NT4, but this rule does not apply to
4134Administrator (or perhaps other users in the Administrators group.. ::grin::).
4135
4136 Ok, so far we've covered some pretty good information, but lets go into that new product that
4137microsoft loves so much. The product they really hyped.. NTFS (NewTechnologiesFileSystem).
4138First of all, NTFS is a rip off of the OS/2 file system, HPFS. No biggie, lets not get picky. Anyhow,
4139NTFS is actually a beautiful thing, if used properly. NTFS allows administrator to not only put
4140access permissions on folders, but it also allows for access permissions on individual files within
4141that folder.
4142
4143Example: Jane and Ralph both have access to the folder 'Shoes'. Theres only one file within the
4144'shoes' folder. Only jane has access to this one file, Ralph does not. So when Ralph opens the
4145'shoe' folder, it appears empty, but when Jane opens the 'shoe' folder, the file is there.
4146
4147Now, If an administrator does not set permissions on files within a folder but you know the exact
4148path to the file, you can copy the file out of the folder onto a FAT (File Allocation Table) system,
4149successfully bypassing the security. Example:
4150
4151The folder 'Shoes' has permissions on it. You do not have access permission to the folder, BUT if
4152you typed:
4153
4154 copy c:\shoes\secure.txt a:\
4155
4156 It would allow you to copy the file. Pretty neat huh?
4157
4158I have heard that the latest NT4 patches have corrected this problem, I will let ya know when I get
4159a chance to test it out.
4160
4161File Sharing, I love those words. SMB file and print server protocols used by NT are harder to
4162spoof than the NFS implementation on Unix systems. It is possible that a gateway (and I dont
4163mean the brand name company) machine could spoof an SMB session, then read and write any
4164files to which the true user of the session had access. -WARNING- This method is not for the
4165beginner.
4166
4167Now, windows allows for this wonderful thing called User Profiles. This allows for users to have
4168login scripts, personalized desktops, etc etc. Now some very personal information can be
4169contained within these profiles. For example, some users put the userid and password that they
4170use for Microsoft Mail onto their logon script, this way when they log into the machine, it auto logs
4171them into their mailbox. User profiles are stored in the %SYSTEMROOT%\SYSTEM32\CONFIG
4172directory and also on a shared directory on the server.
4173
4174Lets discuss our little friend, the special share. NT shares the
4175%SYSTEMROOT%\SYSTEM32\REPL\IMPORT\SCRIPTS directory, this way, users can read
4176their login scripts during login. Under normal default conditions, ANYONE can access this share
4177and read anyone elses login script. So whatever juicy pieces of information are in the login script
4178are now yours. Some other special shares are created depending on other software installed on
4179NT or other servers that NT has to cooperate with. These other shares will probably be discussed
4180in another BlackPaper.
4181
4182Getting lucky with that special account. There is a certain type of NT account that has the ability
4183to BackUp and Restore database and account information. Accounts of this type have the ability
4184to read, modify and write any file in the system. So, if ya cant get the Admin account, who
4185knows... maybe theres a backup operator account. Ya never know.
4186
4187
4188==============Part Two==============
4189===================Manipulation===================
4190
4191
4192[19.0.0] IMPORTANT DISCLAIMER
4193
4194This book was cut in HALF.
4195
4196HALF
4197
4198There are 7 more chapters with huge amounts of hacking content in the full version
4199
4200-Demitri