<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Support Blog &#187; Windows Server 2003</title>
	<atom:link href="http://www.aionsolution.com/blog/category/windows-server-2003/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.aionsolution.com/blog</link>
	<description>[IT Problem Resolved]</description>
	<lastBuildDate>Mon, 12 Dec 2011 10:34:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>退出時自動清除分頁檔案</title>
		<link>http://www.aionsolution.com/blog/windows-server-2003/%e9%80%80%e5%87%ba%e6%99%82%e8%87%aa%e5%8b%95%e6%b8%85%e9%99%a4%e5%88%86%e9%a0%81%e6%aa%94%e6%a1%88/</link>
		<comments>http://www.aionsolution.com/blog/windows-server-2003/%e9%80%80%e5%87%ba%e6%99%82%e8%87%aa%e5%8b%95%e6%b8%85%e9%99%a4%e5%88%86%e9%a0%81%e6%aa%94%e6%a1%88/#comments</comments>
		<pubDate>Thu, 28 May 2009 10:51:06 +0000</pubDate>
		<dc:creator>Dick</dc:creator>
				<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.aionsolution.com/blog/?p=88</guid>
		<description><![CDATA[1 .開始 -&#62; 執行 -&#62; gpedit.msc 2. [電腦設定] -&#62; [Windows 設定] -&#62; [安全性設定] -&#62; [本機原則] -&#62;[安全性選項] 3. [關機: 清除虛擬記憶體分頁檔] -&#62; 設定為 [已啟用]]]></description>
			<content:encoded><![CDATA[<p>1 .開始 -&gt; 執行 -&gt; gpedit.msc<br />
2. [電腦設定] -&gt; [Windows 設定] -&gt; [安全性設定] -&gt; [本機原則] -&gt;[安全性選項]<br />
3. [關機: 清除虛擬記憶體分頁檔] -&gt; 設定為 [已啟用]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aionsolution.com/blog/windows-server-2003/%e9%80%80%e5%87%ba%e6%99%82%e8%87%aa%e5%8b%95%e6%b8%85%e9%99%a4%e5%88%86%e9%a0%81%e6%aa%94%e6%a1%88/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>禁用Guest 帳戶</title>
		<link>http://www.aionsolution.com/blog/windows-server-2003/%e7%a6%81%e7%94%a8guest-%e5%b8%b3%e6%88%b6/</link>
		<comments>http://www.aionsolution.com/blog/windows-server-2003/%e7%a6%81%e7%94%a8guest-%e5%b8%b3%e6%88%b6/#comments</comments>
		<pubDate>Thu, 28 May 2009 10:47:54 +0000</pubDate>
		<dc:creator>Dick</dc:creator>
				<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.aionsolution.com/blog/?p=85</guid>
		<description><![CDATA[1 .開始 -&#62; 執行 -&#62; gpedit.msc 2. [電腦設定] -&#62; [Windows 設定] -&#62; [安全性設定] -&#62; [本機原則] -&#62;[安全性選項] 3. [帳戶: Guest 帳戶狀態] -&#62; 設定為 [已停用]]]></description>
			<content:encoded><![CDATA[<p>1 .開始 -&gt; 執行 -&gt; gpedit.msc<br />
2. [電腦設定] -&gt; [Windows 設定] -&gt; [安全性設定] -&gt; [本機原則] -&gt;[安全性選項]<br />
3. [帳戶: Guest 帳戶狀態] -&gt; 設定為 [已停用]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aionsolution.com/blog/windows-server-2003/%e7%a6%81%e7%94%a8guest-%e5%b8%b3%e6%88%b6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>將Administrator 帳戶改名</title>
		<link>http://www.aionsolution.com/blog/windows-server-2003/%e5%b0%87administrator-%e5%b8%b3%e6%88%b6%e6%94%b9%e5%90%8d/</link>
		<comments>http://www.aionsolution.com/blog/windows-server-2003/%e5%b0%87administrator-%e5%b8%b3%e6%88%b6%e6%94%b9%e5%90%8d/#comments</comments>
		<pubDate>Thu, 28 May 2009 10:39:48 +0000</pubDate>
		<dc:creator>Dick</dc:creator>
				<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.aionsolution.com/blog/?p=82</guid>
		<description><![CDATA[1 .開始 -&#62; 執行 -&#62; gpedit.msc 2. [電腦設定] -&#62; [Windows 設定] -&#62; [安全性設定] -&#62; [本機原則] -&#62;[安全性選項] 3. [重新命名系統管理員帳戶]]]></description>
			<content:encoded><![CDATA[<p>1 .開始 -&gt; 執行 -&gt; gpedit.msc<br />
2. [電腦設定] -&gt; [Windows 設定] -&gt; [安全性設定] -&gt; [本機原則] -&gt;[安全性選項]<br />
3. [重新命名系統管理員帳戶]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aionsolution.com/blog/windows-server-2003/%e5%b0%87administrator-%e5%b8%b3%e6%88%b6%e6%94%b9%e5%90%8d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>設定群組原則加強系統密碼安全</title>
		<link>http://www.aionsolution.com/blog/windows-server-2003/%e8%a8%ad%e5%ae%9a%e7%be%a4%e7%b5%84%e5%8e%9f%e5%89%87%e5%8a%a0%e5%bc%b7%e7%b3%bb%e7%b5%b1%e5%af%86%e7%a2%bc%e5%ae%89%e5%85%a8/</link>
		<comments>http://www.aionsolution.com/blog/windows-server-2003/%e8%a8%ad%e5%ae%9a%e7%be%a4%e7%b5%84%e5%8e%9f%e5%89%87%e5%8a%a0%e5%bc%b7%e7%b3%bb%e7%b5%b1%e5%af%86%e7%a2%bc%e5%ae%89%e5%85%a8/#comments</comments>
		<pubDate>Thu, 28 May 2009 09:43:56 +0000</pubDate>
		<dc:creator>Dick</dc:creator>
				<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.aionsolution.com/blog/?p=75</guid>
		<description><![CDATA[1. 開始 -&#62; 執行 -&#62; 輸入 “gpedit.msc” -&#62; 確定 2. 展開: [電腦設定] -&#62; [Windows 設定] -&#62; [安全性設定] -&#62; [帳戶原則] -&#62; [密碼原則] 3. 按兩下 [密碼必須符合複雜性需求]原則 4. 打開其內容對話框, 將內容設定為 [已啟用] -&#62; 確定 5. 按兩下[最小密碼長度] -&#62; 設定長度]]></description>
			<content:encoded><![CDATA[<p>1. 開始 -&gt; 執行 -&gt; 輸入 “gpedit.msc” -&gt; 確定<br />
2. 展開:<br />
[電腦設定] -&gt; [Windows 設定] -&gt; [安全性設定] -&gt; [帳戶原則] -&gt; [密碼原則]<br />
3. 按兩下 [密碼必須符合複雜性需求]原則<br />
4. 打開其內容對話框, 將內容設定為 [已啟用] -&gt; 確定<br />
5. 按兩下[最小密碼長度] -&gt; 設定長度</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aionsolution.com/blog/windows-server-2003/%e8%a8%ad%e5%ae%9a%e7%be%a4%e7%b5%84%e5%8e%9f%e5%89%87%e5%8a%a0%e5%bc%b7%e7%b3%bb%e7%b5%b1%e5%af%86%e7%a2%bc%e5%ae%89%e5%85%a8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Migrate Workgroup to Domain</title>
		<link>http://www.aionsolution.com/blog/windows-server-2003/migrate-workgroup-to-domain/</link>
		<comments>http://www.aionsolution.com/blog/windows-server-2003/migrate-workgroup-to-domain/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 12:03:37 +0000</pubDate>
		<dc:creator>aionman</dc:creator>
				<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows XP]]></category>
		<category><![CDATA[Domain]]></category>
		<category><![CDATA[Workgroup]]></category>

		<guid isPermaLink="false">http://www.aionsolution.com/blog/?p=113</guid>
		<description><![CDATA[1) Reboot and log onto the machine as local admin. Copy the profile of the local user.(old user profile) Name it “copyofusername” or something similar. (optional) 2) Join the domain (under local admin as Domain Administrator). Reboot. Login as Domain Admin. 3) Add domain users to local admin group. Log off. 4) Log on as [...]]]></description>
			<content:encoded><![CDATA[<p><span class="Apple-style-span" style="border-collapse: separate; color: #333333; font-family: 'Trebuchet MS'; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;">1) Reboot and log onto the machine as local admin. Copy the profile of the local user.(old user profile) Name it “copyofusername” or something similar. (optional)<br />
2) Join the domain (under local admin as Domain Administrator). Reboot. Login as Domain Admin.<br />
3) Add domain users to local admin group. Log off.<br />
4) Log on as the domain user. Reboot.<br />
5) Log on as domain admin. Rename the new domain profile to “username.domain.old” or something similar. Rename the “copyofusername” file to whatever the new domain user profile was called. Log off.<br />
6) Log on as domain user.Note: Everything should work as it did before. You may need the users email username and password.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aionsolution.com/blog/windows-server-2003/migrate-workgroup-to-domain/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Active Directory database corrupted</title>
		<link>http://www.aionsolution.com/blog/windows-server-2003/active-directory-database-corrupted/</link>
		<comments>http://www.aionsolution.com/blog/windows-server-2003/active-directory-database-corrupted/#comments</comments>
		<pubDate>Wed, 22 Apr 2009 02:42:30 +0000</pubDate>
		<dc:creator>aionman</dc:creator>
				<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[Repair AD]]></category>

		<guid isPermaLink="false">http://www.aionsolution.com/blog/?p=1</guid>
		<description><![CDATA[Active Directory database corruption is nasty. If you don&#8217;t have your image backup or any system state backup. It&#8217;s going to cost you time (and money). We have faced this recently, here are some of the approaches and links to find the solution. http://www.mombu.com/microsoft/windows-2000-active-directory/t-event-id-474-inconsistent-ntdsdit-151743.html If you have a recent backup, we recommend you to perform [...]]]></description>
			<content:encoded><![CDATA[<p>Active Directory database corruption is nasty. If you don&#8217;t have your image backup or any system state backup. It&#8217;s going to cost you time (and money).</p>
<p>We have faced this recently, here are some of the approaches and links to find the solution.</p>
<p><a href="http://www.mombu.com/microsoft/windows-2000-active-directory/t-event-id-474-inconsistent-ntdsdit-151743.html">http://www.mombu.com/microsoft/windows-2000-active-directory/t-event-id-474-inconsistent-ntdsdit-151743.html</a></p>
<p>If you have a recent backup, we recommend you to perform restore operation right away. However if the backup is not recent, and you&#8217;ll loose many objects.</p>
<p>You can<span> </span>try to repair the Database, In some situation, certain configurations will<span> </span>be lost with this procedure.</p>
<p>Before you start the computer in Directory Services Restore Mode, obtain the<span> </span><br />
password for the offline administrator account.</p>
<p>For more information about how to change the password in Windows Server<span> </span><br />
2003, click the following article number to view the article in the<span> </span>Microsoft Knowledge Base <a style="color: #ff5501;" href="http://support.microsoft.com/kb/322672/" target="_blank">http://support.microsoft.com/kb/322672/</a></p>
<p>&#8220;Directory Services cannot start&#8221; error message when you start your<span> </span><br />
Windows-based or SBS-based domain controller<br />
<a style="color: #ff5501;" href="http://support.microsoft.com/?id=258062" target="_blank">http://support.microsoft.com/?id=258062</a></p>
<p>Next step:</p>
<p>How to Recover the Database and if it fails try How to Repair the Database<span> </span><br />
(Be careful.  Read carefully)</p>
<p><a style="color: #ff5501;" href="http://support.microsoft.com/default.aspx?scid=kb;en-us;315131" target="_blank">http://support.microsoft.com/default…b;en-us;315131</a></p>
<p>How to complete a semantic database analysis for the Active Directory<span> </span><br />
database by using Ntdsutil.exe<br />
<a style="color: #ff5501;" href="http://support.microsoft.com/default.aspx?scid=kb;en-us;315136" target="_blank">http://support.microsoft.com/default…b;en-us;315136</a></p>
<p>If you fail to repair a corrupted Active Directory, try the following:<br />
You may try the following steps to recover the corrupted Active Directory.</p>
<p>1. Reboot the server and press F8. Choose Directory Services Restore Mode<span> </span><br />
from the Menu.<br />
2. Check the physical location of the Winnt\NTDS\ folder.<br />
3. Check the permissions on the \Winnt\NTDS folder.</p>
<p>The default permissions are:</p>
<p>Administrators &#8211; Full Control<br />
System &#8211; Full Control</p>
<p>4. Check the Winnt\Sysvol\Sysvol folder to make sure it is shared.<br />
5. Check the permissions on the Winnt\Sysvol\Sysvol share.</p>
<p>The default permissions are:</p>
<p>Share Permissions:<br />
Administrators &#8211; Full Control<br />
Authenticated Users &#8211; Full Control<br />
Everyone &#8211; Read</p>
<p>NTFS Permissions:<br />
Administrators &#8211; Full Control<br />
Authenticated Users &#8211; Read &amp; Execute, List Folder Contents, Read<br />
Creator Owner &#8211; none<br />
Server Operators &#8211; Read &amp; Execute, List Folder Contents, Read<br />
System &#8211; Full Control</p>
<p>Note: You may not be able to change the permissions on these folders if the<span> </span><br />
Active Directory database is unavailable because it is damaged, however it<span> </span><br />
is best to know if the permissions are set correctly before you start the<span> </span><br />
recovery process, as it may not be the database that is the problem.</p>
<p>6. Make sure there is a folder in the Sysvol share labeled with the correct<span> </span><br />
name for their domain.<br />
7. Open a command prompt and run NTDSUTIL to verify the paths for the<span> </span><br />
NTDS.dit file. These should match the physical structure from Step 2</p>
<p>To check the file paths type the following commands:</p>
<p>NTDSUTIL &lt;enter&gt;<br />
Files &lt;enter&gt;<br />
Info &lt;enter&gt;</p>
<p>The output should look similar to:</p>
<p>Drive Information:</p>
<p>C:\ NTFS (Fixed Drive) free (2.9 Gb) total (3.9 Gb)<br />
D:\ NTFS (Fixed Drive) free (3.6 Gb) total (3.9 Gb)</p>
<p>DS Path Information:</p>
<p>Database : C:\WINNT\NTDS\ntds.dit &#8211; 10.1 Mb<br />
Backup dir: C:\WINNT\NTDS\dsadata.bak<br />
Working dir: C:\WINNT\NTDS<br />
Log dir : C:\WINNT\NTDS &#8211; 30.0 Mb total<br />
res2.log &#8211; 10.0 Mb<br />
res1.log &#8211; 10.0 Mb<br />
edb.log &#8211; 10.0 Mb</p>
<p>This information is pulled directly from the registry and mismatched paths<span> </span><br />
will cause Active Directory not to start. Type Quit to end the NTDSUTIL<span> </span><br />
session.</p>
<p>8. Rename the edb.chk file and try to boot to Normal mode. If that fails,<span> </span><br />
proceed with the next steps.</p>
<p>9. Reboot into Directory Services Restore mode again. At the command prompt,<span> </span><br />
use the ESENTUTL to check the integrity of the database.<br />
NOTE: You can use NTDSUTIL to check the Integrity, however esentutl is<span> </span><br />
usually more reliable.</p>
<p>Type the following command:<br />
ESENTUTL /g &#8220;&lt;path&gt;\NTDS.dit&#8221; /!10240 /8 /v /x /o &lt;enter&gt;<br />
(Note: Type the path without the quotes).</p>
<p>Note: The default path would be C:\Winnt\NTDS\ntds.dit; however it may be<span> </span><br />
different in some cases.</p>
<p>The output will tell you if the database is inconsistent and may produce a<span> </span><br />
jet_error 1206 stating that the database is corrupt. If the database is<span> </span><br />
inconsistent or corrupt it will need to be recovered or repaired . To<span> </span><br />
recover the database type the following at the command prompt:</p>
<p>NTDSUTIL &lt;enter&gt;<br />
Files&lt;enter&gt;<br />
Recover &lt;enter&gt;</p>
<p>If this fails with an error, type quit until back at the command prompt and<span> </span><br />
repair the database using ESENTUTL by typing the following:</p>
<p>ESENTUTL /p &#8220;&lt;path&gt;\NTDS.dit&#8221; /!10240 /8 /v /x /o &lt;enter&gt;<br />
(Note: Type the path without the quotes).</p>
<p>Note: If you do not put the switches at the end of the command you will<span> </span><br />
most likely get a Jet_error 1213 &#8220;Page size mismatch&#8221; error.</p>
<p>10. Delete the log files in the NTDS directory, but do not delete or move<span> </span><br />
the ntds.dit file.<br />
11. The NTDSUTIL tool needs to be run again to check the Integrity of the<span> </span><br />
database and to perform a Semantic Database analysis.</p>
<p>To check the integrity, at the command prompt type:</p>
<p>NTDSUTIL &lt;enter&gt;<br />
Files &lt;enter&gt;<br />
Integrity &lt;enter&gt;</p>
<p>The output should tell you that the integrity check completed successfully<span> </span><br />
and prompt that you should perform a Semantic Database Analysis.</p>
<p>Type quit.</p>
<p>To perform the Semantic Database Analysis type the following at the NTDSUTIL<span> </span><br />
Prompt type:</p>
<p>Semantic Database Analysis &lt;enter&gt;<br />
Go &lt;enter&gt;</p>
<p>The output will tell you that the Analysis completed successfully.<br />
Type quit and closes the command prompt.</p>
<p>NOTE: If you get errors running the Analysis then type the following at the<span> </span><br />
semantic checker prompt:</p>
<p>semantic checker: go fix &lt;enter&gt;</p>
<p>This puts the checker in Fixup mode, which should fix whatever errors there<span> </span><br />
were.</p>
<p>12. Reboot the server to Normal Mode.</p>
<p>If any of these steps fail to recover the database the only alternative is<span> </span><br />
to perform an Authoritative System State restore from backup in Directory<span> </span><br />
Services Restore mode.</p>
<p>For more information, please refer to the following articles:</p>
<p>315136 HOW TO: Complete a Semantic Database Analysis for the Active<span> </span><br />
Directory<br />
<a style="color: #ff5501;" href="http://support.microsoft.com/?id=315136" target="_blank">http://support.microsoft.com/?id=315136</a></p>
<p>265706 DCDiag and NetDiag in Windows 2000 Facilitate Domain Join and DC<span> </span><br />
Creation<br />
<a style="color: #ff5501;" href="http://support.microsoft.com/?id=265706" target="_blank">http://support.microsoft.com/?id=265706</a></p>
<p>258007 Error Message: Lsass.exe &#8211; System Error : Security Accounts Manager<br />
<a style="color: #ff5501;" href="http://support.microsoft.com/?id=258007" target="_blank">http://support.microsoft.com/?id=258007</a></p>
<p>265089 Event 1168: Windows 2000 DCs Unable to Boot into Active Directory<br />
<a style="color: #ff5501;" href="http://support.microsoft.com/?id=265089" target="_blank">http://support.microsoft.com/?id=265089</a></p>
<p>315131 HOW TO: Use Ntdsutil to Manage Active Directory Files from the<span> </span><br />
Command<br />
<a style="color: #ff5501;" href="http://support.microsoft.com/?id=315131" target="_blank">http://support.microsoft.com/?id=315131</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aionsolution.com/blog/windows-server-2003/active-directory-database-corrupted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How can I disable the Administrative Share creation in Windows NT/2000/XP/2003?</title>
		<link>http://www.aionsolution.com/blog/windows-server-2003/how-can-i-disable-the-administrative-share-creation-in-windows-nt2000xp2003/</link>
		<comments>http://www.aionsolution.com/blog/windows-server-2003/how-can-i-disable-the-administrative-share-creation-in-windows-nt2000xp2003/#comments</comments>
		<pubDate>Sun, 07 Dec 2008 12:01:52 +0000</pubDate>
		<dc:creator>aionman</dc:creator>
				<category><![CDATA[Windows Server 2003]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.aionsolution.com/blog/?p=111</guid>
		<description><![CDATA[How can I disable the Administrative Share creation in Windows NT/2000/XP/2003? Every Windows NT/W2K/XP/2003 machine automatically creates a share for each drive on the system. These shares are hidden, but available with full control to domain administrators. The drive letter, followed by the $ sign is the name, and it is shared from the root. [...]]]></description>
			<content:encoded><![CDATA[<p><span class="Apple-style-span" style="border-collapse: separate; color: #333333; font-family: 'Trebuchet MS'; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 18px; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"></p>
<p style="margin: 0px; padding: 0px 0px 15px;">How can I disable the Administrative Share creation in Windows NT/2000/XP/2003?</p>
<p style="margin: 0px; padding: 0px 0px 15px;">Every Windows NT/W2K/XP/2003 machine automatically creates a share for each drive on the system. These shares are hidden, but available with full control to domain administrators. The drive letter, followed by the $ sign is the name, and it is shared from the root. When trying to attain a highly secure network, you may wish to address this potential security issue by disabling these shares, or at least restricting their permissions to specific users or services.</p>
<p style="margin: 0px; padding: 0px 0px 15px;">The default-hidden shares are:</p>
<ul>
<li><strong>C$ D$ E$</strong><span class="Apple-converted-space"> </span>- Root of each partition. For a Windows NT workstation/W2K/2003/XP Professional computer only members of the Administrators or Backup Operators group can connect to these shared folders. For a Windows NT Server/W2K Server computer, members of the Server Operators group can also connect to these shared folders.</li>
<li><strong>ADMIN$</strong><span class="Apple-converted-space"> </span>- %SYSTEMROOT% This share is used by the system during any remote administration of a computer. The path of this resource is always the path to the W2K/NT system root (the directory in which W2K/NT is installed usually C:\Winnt and in XP it’s C:\Windows).</li>
<li><strong>FAX$</strong><span class="Apple-converted-space"> </span>- On W2K Server, this used by fax clients in the process of sending a fax. The shared folder temporarily caches files and accesses cover pages stored on the server.</li>
<li><strong>IPC$</strong><span class="Apple-converted-space"> </span>- Temporary connections between servers using named pipes essential for communication between programs. It is used during remote administration of a computer and when viewing a computer’s shared resources. This share can be very dangerous and can be used to extract large amounts of information about your network, even by an anonymous account.</li>
<li><strong>NetLogon</strong><span class="Apple-converted-space"> </span>- This share is used by the Net Logon service of a W2K, 2003 and NT Server computer while processing domain logon requests, and by Pre-W2K computers when running logon scripts.</li>
<li><strong>PRINT$</strong><span class="Apple-converted-space"> </span>- %SYSTEMROOT%\SYSTEM32\SPOOL\DRIVERS Used during remote administration of printers.</li>
</ul>
<p style="margin: 0px; padding: 0px 0px 15px;">It is possible to simply remove the share from Server Manager (in NT) or Shared Folders (in W2K/XP/2003) but the problem with this method is that the shares will automatically be recreated when the machine reboots.</p>
<p style="margin: 0px; padding: 0px 0px 15px;">You can disable the automatic administrative share creation via Group Policy, but this is a much simpler way:</p>
<p style="margin: 0px; padding: 0px 0px 15px;">In order to disable these shares permanently, a registry edit will be necessary.</p>
<h2 style="border-bottom: 1px dotted #cccccc; margin: 0px 0px 2px; color: #59770e; letter-spacing: -1px; font-family: 'Trebuchet MS',Tahoma,Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 190%; line-height: 100%; font-size-adjust: none; font-stretch: normal; -x-system-font: none; padding-bottom: 3px;" dir="ltr">Servers</h2>
<p style="margin: 0px; padding: 0px 0px 15px;">For NT 4.0/W2K/Windows Server 2003s, the change is:</p>
<blockquote>
<p style="margin: 0px; padding: 0px 0px 15px;">Hive: HKEY_LOCAL_MACHINE<br />
Key: SYSTEM\CurrentControlSet\Services\LanManServer\Parameters<br />
Name: AutoShareServer<br />
Data Type: REG_DWORD<br />
Value: 0</p></blockquote>
<p style="margin: 0px; padding: 0px 0px 15px;"><strong>Idiot proof note:<span class="Apple-converted-space"> </span></strong>If you can’t find the value in the registry under the exact location (i.e. it does not exist) &#8211; please right click in the right pane of the window and create it.</p>
<p style="margin: 0px; padding: 0px 0px 15px;"><strong>Note:<span class="Apple-converted-space"> </span></strong>A reboot is necessary for this to take effect.</p>
<h2 style="border-bottom: 1px dotted #cccccc; margin: 0px 0px 2px; color: #59770e; letter-spacing: -1px; font-family: 'Trebuchet MS',Tahoma,Arial; font-style: normal; font-variant: normal; font-weight: normal; font-size: 190%; line-height: 100%; font-size-adjust: none; font-stretch: normal; -x-system-font: none; padding-bottom: 3px;" dir="ltr">Workstations</h2>
<p style="margin: 0px; padding: 0px 0px 15px;">For NT 4.0 Workstation/W2K Pro/XP Pro, the change is:</p>
<blockquote>
<p style="margin: 0px; padding: 0px 0px 15px;">Hive: HKEY_LOCAL_MACHINE<br />
Key: SYSTEM\CurrentControlSet\Services\LanManServer\Parameters<br />
Name: AutoShareWks<br />
Data Type: REG_DWORD<br />
Value: 0</p></blockquote>
<p style="margin: 0px; padding: 0px 0px 15px;"><strong>A double idiot proof note:<span class="Apple-converted-space"> </span></strong>If you can’t find the value in the registry under the exact location (i.e. it does not exist) &#8211; please right click in the right pane of the window and create it.</p>
<p style="margin: 0px; padding: 0px 0px 15px;"><strong>Note:<span class="Apple-converted-space"> </span></strong>Again, a reboot is necessary for this to take effect.</p>
<p style="margin: 0px; padding: 0px 0px 15px;">If you want the administrative shares to be re-created, you can change the value back to 1.</p>
<p style="margin: 0px; padding: 0px 0px 15px;"><strong>Note:</strong><span class="Apple-converted-space"> </span>Some applications depend on the presence of these shares. If things stop working you’ll know to re-enable the shares.</p>
<p style="margin: 0px; padding: 0px 0px 15px;"><strong>Security note:</strong><span class="Apple-converted-space"> </span>Unfortunately this registry hack does NOT stop the IPC$ share and this is a share that is often used by hackers to enumerate systems before attack since it can yield a wealth of information about your system names, your user names, and more. If your ACL permissions are not correct or you haven’t disabled anonymous user access or you haven’t disabled the guest account then this port can lead to total system compromise within minutes!</p>
<p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aionsolution.com/blog/windows-server-2003/how-can-i-disable-the-administrative-share-creation-in-windows-nt2000xp2003/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

