Auditing Windows 2003 Servers for Disabled USB Drives and AutoRun CD-ROM
by Ron Gula on January 8, 2007
Many organizations have IT configuration polices that require CDs and USB drives to be disabled. This blog entry discusses a simple way to use a Nessus 3 .audit file to test a Windows 2003 server for the correct registry settings that disable "AutoRun" of programs on CDs as well as disables USB drives.
Windows 2003 Registry Settings
On Windows 2003 servers, the following registry setting controls "AutoRun" for CD drives:
HKLM\SYSTEM\CurrentControlSet\Services\Cdrom