need help with local security policy

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
I was messing around with my local security and now I can't browse unc paths :(

for example, I was able to get to \\intranet\files, but now I can't. I can still get to the ip though: \\192.168.0.2\files

what's up? take a look:

Policy Security Setting
Accounts: Administrator account status Enabled
Accounts: Guest account status Disabled
Accounts: Limit local account use of blank passwords to console logon only Enabled
Accounts: Rename administrator account Administrator
Accounts: Rename guest account Guest
Audit: Audit the access of global system objects Disabled
Audit: Audit the use of Backup and Restore privilege Disabled
Audit: Shut down system immediately if unable to log security audits Disabled
DCOM: Machine Access Restrictions in Security Descriptor Definition Language (SDDL) syntax Not defined
DCOM: Machine Launch Restrictions in Security Descriptor Definition Language (SDDL) syntax Not defined
Devices: Allow undock without having to log on Enabled
Devices: Allowed to format and eject removable media Administrators
Devices: Prevent users from installing printer drivers Disabled
Devices: Restrict CD-ROM access to locally logged-on user only Disabled
Devices: Restrict floppy access to locally logged-on user only Disabled
Devices: Unsigned driver installation behavior Warn but allow installation
Domain controller: Allow server operators to schedule tasks Not defined
Domain controller: LDAP server signing requirements Not defined
Domain controller: Refuse machine account password changes Not defined
Domain member: Digitally encrypt or sign secure channel data (always) Enabled
Domain member: Digitally encrypt secure channel data (when possible) Enabled
Domain member: Digitally sign secure channel data (when possible) Enabled
Domain member: Disable machine account password changes Disabled
Domain member: Maximum machine account password age 30 days
Domain member: Require strong (Windows 2000 or later) session key Disabled
Interactive logon: Do not display last user name Enabled
Interactive logon: Do not require CTRL+ALT+DEL Disabled
Interactive logon: Message text for users attempting to log on
Interactive logon: Message title for users attempting to log on Not defined
Interactive logon: Number of previous logons to cache (in case domain controller is not available) 10 logons
Interactive logon: Prompt user to change password before expiration 14 days
Interactive logon: Require Domain Controller authentication to unlock workstation Disabled
Interactive logon: Require smart card Not defined
Interactive logon: Smart card removal behavior No Action
Microsoft network client: Digitally sign communications (always) Disabled
Microsoft network client: Digitally sign communications (if server agrees) Enabled
Microsoft network client: Send unencrypted password to third-party SMB servers Disabled
Microsoft network server: Amount of idle time required before suspending session 15 minutes
Microsoft network server: Digitally sign communications (always) Disabled
Microsoft network server: Digitally sign communications (if client agrees) Disabled
Microsoft network server: Disconnect clients when logon hours expire Enabled
Network access: Allow anonymous SID/Name translation Disabled
Network access: Do not allow anonymous enumeration of SAM accounts Enabled
Network access: Do not allow anonymous enumeration of SAM accounts and shares Enabled
Network access: Do not allow storage of credentials or .NET Passports for network authentication Disabled
Network access: Let Everyone permissions apply to anonymous users Disabled
Network access: Named Pipes that can be accessed anonymously
Network access: Remotely accessible registry paths
Network access: Shares that can be accessed anonymously
Network access: Sharing and security model for local accounts Guest only - local users authenticate as Guest
Network security: Do not store LAN Manager hash value on next password change Disabled
Network security: Force logoff when logon hours expire Disabled
Network security: LAN Manager authentication level Send LM & NTLM responses
Network security: LDAP client signing requirements Negotiate signing
Network security: Minimum session security for NTLM SSP based (including secure RPC) clients No minimum
Network security: Minimum session security for NTLM SSP based (including secure RPC) servers No minimum
Recovery console: Allow automatic administrative logon Disabled
Recovery console: Allow floppy copy and access to all drives and all folders Disabled
Shutdown: Allow system to be shut down without having to log on Disabled
Shutdown: Clear virtual memory pagefile Disabled
System cryptography: Use FIPS compliant algorithms for encryption, hashing, and signing Disabled
System objects: Default owner for objects created by members of the Administrators group Object creator
System objects: Require case insensitivity for non-Windows subsystems Enabled
System objects: Strengthen default permissions of internal system objects (e.g. Symbolic Links) Enabled
 

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
ok, I just matched it up to a fresh install and changed all the settings to default.

still can't browse unc....not sure what else is wrong :(

DNS is setup properly and netbios turned on.

here's my services list:

Name Status Startup Type Log On As
Adobe LM Service Manual Local System
Alerter Disabled Local Service
Application Layer Gateway Service Started Manual Local Service
Application Management Manual Local System
Asmirvpkrbv Disabled Local System
ASP.NET State Service Manual Network Service
Ati HotKey Poller Disabled Local System
Automatic Updates Disabled Local System
Background Intelligent Transfer Service Disabled Local System
Broadcom ASF IP monitoring service v6.0.3 Disabled Local System
ClipBook Disabled Local System
COM+ Event System Started Manual Local System
COM+ System Application Manual Local System
Computer Browser Manual Local System
Cryptographic Services Started Automatic Local System
DCOM Server Process Launcher Started Automatic Local System
DHCP Client Started Automatic Local System
Distributed Link Tracking Client Started Automatic Local System
Distributed Transaction Coordinator Manual Network Service
DNS Client Started Automatic Network Service
Error Reporting Service Disabled Local System
Event Log Started Automatic Local System
Fast User Switching Compatibility Disabled Local System
FTP Publishing Disabled Local System
Help and Support Manual Local System
HID Input Service Started Automatic Local System
HTTP SSL Disabled Local System
IMAPI CD-Burning COM Service Manual Local System
Indexing Service Started Automatic Local System
IPSEC Services Started Automatic Local System
Logical Disk Manager Started Automatic Local System
Logical Disk Manager Administrative Service Manual Local System
Machine Debug Manager Disabled Local System
Messenger Disabled Local System
MS Software Shadow Copy Provider Manual Local System
Net Logon Started Automatic Local System
NetMeeting Remote Desktop Sharing Disabled Local System
Network Connections Started Manual Local System
Network DDE Disabled Local System
Network DDE DSDM Disabled Local System
Network Location Awareness (NLA) Started Manual Local System
Network Provisioning Service Manual Local System
NT LM Security Support Provider Manual Local System
Office Source Engine Disabled Local System
Performance Logs and Alerts Manual Network Service
Plug and Play Started Automatic Local System
Portable Media Serial Number Service Disabled Local System
Print Spooler Manual Local System
Protected Storage Started Automatic Local System
QoS RSVP Manual Local System
Remote Access Auto Connection Manager Manual Local System
Remote Access Connection Manager Started Manual Local System
Remote Desktop Help Session Manager Disabled Local System
Remote Packet Capture Protocol v.0 (experimental) Disabled Local System
Remote Procedure Call (RPC) Started Automatic Network Service
Remote Procedure Call (RPC) Locator Manual Network Service
Remote Registry Disabled Local Service
Removable Storage Manual Local System
Routing and Remote Access Disabled Local System
SavRoam Manual Local System
Secondary Logon Disabled Local System
Security Accounts Manager Started Automatic Local System
Security Center Automatic Local System
Server Started Manual Local System
Shell Hardware Detection Started Automatic Local System
Smart Card Disabled Local Service
SSDP Discovery Service Started Manual Local Service
Symantec AntiVirus Started Automatic Local System
Symantec AntiVirus Definition Watcher Started Automatic Local System
Symantec Event Manager Started Automatic Local System
Symantec Network Drivers Service Manual Local System
Symantec Password Validation Manual Local System
Symantec Settings Manager Started Automatic Local System
Symantec SPBBCSvc Started Automatic Local System
System Event Notification Started Automatic Local System
System Restore Service Disabled Local System
Task Scheduler Started Automatic Local System
TCP/IP NetBIOS Helper Disabled Local Service
Telephony Started Manual Local System
Telnet Disabled Local System
Terminal Services Disabled Local System
Themes Started Automatic Local System
Uninterruptible Power Supply Manual Local System
Universal Plug and Play Device Host Manual Local Service
Volume Shadow Copy Manual Local System
WebClient Started Automatic Local Service
Windows Audio Started Automatic Local System
Windows Firewall/Internet Connection Sharing (ICS) Started Automatic Local System
Windows Image Acquisition (WIA) Started Automatic Local System
Windows Installer Manual Local System
Windows Management Instrumentation Started Automatic Local System
Windows Management Instrumentation Driver Extensions Manual Local System
Windows Time started Automatic Local System
Windows User Mode Driver Framework Disabled Local Service
Wireless Zero Configuration Disabled Local System
WLTRYSVC Disabled Local System
WMI Performance Adapter Manual Local System
Workstation Started Manual Local System
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
Your services are definitely not at the defaults.

The problem is TCP/IP Netbios Helper. That needs to be started and set to automatic.
 

FreshPrince

Diamond Member
Dec 6, 2001
8,361
1
0
Originally posted by: stash
Your services are definitely not at the defaults.

The problem is TCP/IP Netbios Helper. That needs to be started and set to automatic.

ah, I think you're right. I will give that a try tomorrow.

as always, you da man!

thx :)