
105
Subkey Registry Value Entry
Format
Recommended Value (Decimal)
AutoRun
DWORD
0
Vulnerability:
To prevent a possible malicious program from starting when media is inserted, the
Group Policy disables Autorun on all drives. An attacker with physical access to the system could
insert an Autorun enabled DVD or CD into the computer that will then automatically launch malicious
code. This malicious program could contain whatever code the attacker wishes.
Countermeasure:
Configure
MSS: Disable Autorun for all drives
to a value of
255, disable
Autorun for all drives.
The possible values for this Registry value are:
•
A range of hexadecimal values
For more information, see Microsoft Knowledge Base article Q 330135, "The
AutoRun or AutoPlay Feature Does Not Work."
In the SCE UI, following list of options is available:
•
Null, allow Autorun
•
255, disable Autorun for all drives
•
Not Defined
Potential Impact:
Autorun will no longer work when Autorun-enabled discs are inserted into the
computer.
2.8.6.6
Screensaver Password Settings
Make Screensaver Password Protection Immediate: The time in seconds
before the screen saver grace period expires (0 recommended)
This entry appears as
MSS: The time in seconds before the screen saver grace period expires (0
recommended)
in the SCE. Windows includes a grace period between when the screen saver is
launched, and when the console is actually locked automatically if screen saver locking is enabled.
The following registry value entries have been added to the template file to the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\Software\Microsoft\WindowsNT\CurrentVersion\Winlogon\
Subkey Registry Value Entry
Format
Recommended Value (Decimal)
ScreenSaverGracePeriod
String
0
Vulnerability
:
The default grace period allowed for user movement before the screen-saver lock
takes effect is five seconds. Leaving the grace period in the default setting makes the computer
vulnerable to a potential attack from someone walking up to the console to attempt to log onto the
system before the lock takes effect. An entry to the registry can be made to adjust the length of the
grace period.
Countermeasure
:
Configure
MSS: The time in seconds before the screen saver grace period
expires (0 recommended)
to a value of
0
. The possible values for this Registry value are: