Check: 3.021
Windows XP STIG:
3.021
(in versions v6 r1.32 through v1 r0)
Title
Anonymous access to the event logs is not restricted. (Cat II impact)
Discussion
By default, the Windows event logs may be viewed over the network by an anonymous user. This method of access over the network is communicating through the Server service which has SYSTEM access to the actual log files.
Check Content
Analyze the system using the Security Configuration and Analysis snap-in. Expand the Security Configuration and Analysis tree view. Navigate to Event Logs -> Settings for Event Logs. If the value for “Prevent local guests group from accessing application log” is not set to “Enabled”, then this is a finding. If the value for “Prevent local guests group from accessing security log” is not set to “Enabled”, then this is a finding. If the value for “Prevent local guests group from accessing system log” is not set to “Enabled”, then this is a finding.
Fix Text
Configure the system to prevent guest access to the Event logs.
Additional Identifiers
Rule ID: SV-1095r1_rule
Vulnerability ID: V-1095
Group Title: Restrict Event Log Access over the Network
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |