[NT] Odd Behavior in Windows XP Home (Security Vulnerability, Shares)
From: support@securiteam.comDate: 01/25/02
- Previous message: support@securiteam.com: "[NT] Serious Privacy Leak in Python for Windows"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Fri, 25 Jan 2002 14:42:33 +0100 (CET)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Odd Behavior in Windows XP Home (Security Vulnerability, Shares)
------------------------------------------------------------------------
SUMMARY
The Guest account in Windows XP Home Edition and Windows XP Professional
(when not joined on a domain) serves several special functions that relate
to security and network shares. Thus if you in the Control Panel, turn off
the Guest account (which removes the listing of the Guest account from the
Fast User Switching Welcome screen) the Guest account will not be
disabled. This would open the host to attack through the Guest account.
DETAILS
An unexpected behavior has been observed when configuring Windows XP Home
Edition. It appears that disabling the Guest account (from the User
Accounts tool) only removes the Log-On Local right. Guest users are still
able to connect to shared resources across the network.
Microsoft Knowledge Base article
<http://www.microsoft.com/technet/support/kb.asp?ID=300489> Q300489
describes this behavior and states that it is by design.
This could lead to a compromising of the host, since Guest users are able
to access shared directories, and store files there.
Workaround:
Change the password of the Guest account to a difficult to guess one.
ADDITIONAL INFORMATION
The information has been provided by <mailto:johnson.jc.1@PG.COM> Cullen
Johnson.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NT] Serious Privacy Leak in Python for Windows"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- Re: permissions anomaly in XP noted by W2K user
... John, ... If one used NTFS as the filesystem then it does have the ...
mapped to the Guest account. ... > successful if only I could provide some sort of security
on the folders he ... (microsoft.public.windowsxp.security_admin) - RE: Internet security on "hotspots"
... there's a setting in the security policy under Network Access where ...
Now if we're talking shares, anonymous never did have access in most cases, ... Disabling
the guest account - it's been disabled by default since NT 3.5, ... (Focus-Microsoft) - Re: Anonymous, Guest login problems!!!
... they happen like 15 during a period of 3-4 minutes, always success ... policy,
as set in the local security policy. ... >> deleting the guest account but
it's not possible to delete ... (microsoft.public.windowsxp.security_admin) - Re: Anonymous Acccess to File Share on Windows Server 2003
... This can be configured in Local Security Policy via secpol.msc. ... thing I
did was give the guest account a password. ... > Password authentication pop
up box does not appear. ... > server does not care who is trying to access the share
because everyone is ... (microsoft.public.windows.server.security) - Re: Detecting rootkits?
... Root kit is typically a "Unix" term. ... If someone has enabled the guest
account ... or has the password to the Administrator account, they they "own" a Windows
box. ... In general Download Microsoft Baseline Security Advisor ... (microsoft.public.win2000.security)