RE: Null session in Windows XP

From: Evans, TJ (tjevans@kpmg.com)
Date: 03/27/02


From: "Evans, TJ" <tjevans@kpmg.com>
To: Tomasz Polus <Tomasz_Polus@bsi.net.pl>, FOCUS-MS@securityfocus.com
Date: Wed, 27 Mar 2002 10:57:30 -0500

OOC - WinXP Pro or Home?
(I use Pro, and the following worked for me ... )

Have you tried using the Local Security Policy snapin?
Security Options, Network Access:
        Allow Anonymous ... (1 entry, should set to
disabled)
And Do Not Allow Anonymous ... (2 entries, should set to
enabled)

Thanks!
TJ

-----Original Message-----
From: Tomasz Polus [mailto:Tomasz_Polus@bsi.net.pl]
Sent: Wednesday, March 27, 2002 3:04 AM
To: FOCUS-MS@securityfocus.com
Subject: Null session in Windows XP

Hi All,

I have a problem with restricting null user access to Windows XP.
I'm aware of all the information from the following articles:
MSKB Q143474: Restricting Information Available to Anonymous
Logon Users
MSKB Q246261: How to Use the RestrictAnonymous Registry Value
in Windows 2000
RestrictAnonymous: Enumeration and the Null User
(http://online.securityfocus.com/infocus/1352)

and of course I set RestrictAnonymous and RestrictNullSessAccess
registry keys properly (2;1). There is no problem in Windows 2000
- these settings deny null user access to my machine.
Unfortunately in Windows XP Professional it doesn't work this way.
Null session still can be established... Can somebody please
explain this to me?

-- 
Tomasz Polus
*****************************************************************************
The information in this email is confidential and may be legally privileged.
It is intended solely for the addressee. Access to this email by anyone else
is unauthorized. 

If you are not the intended recipient, any disclosure, copying, distribution or any action taken or omitted to be taken in reliance on it, is prohibited and may be unlawful. When addressed to our clients any opinions or advice contained in this email are subject to the terms and conditions expressed in the governing KPMG client engagement letter. *****************************************************************************



Relevant Pages

  • Re: Null session in Windows XP
    ... >I have a problem with restricting null user access to Windows XP. ... >Null session still can be established... ...
    (Focus-Microsoft)
  • RE: Null session in Windows XP
    ... Null session in Windows XP ... would fully prevent this enumeration. ... >I have a problem with restricting null user access to Windows XP. ...
    (Focus-Microsoft)
  • Null session in Windows XP
    ... I have a problem with restricting null user access to Windows XP. ... MSKB Q246261: How to Use the RestrictAnonymous Registry Value ...
    (Focus-Microsoft)
  • RE: Null session in Windows XP
    ... Null session in Windows XP ... would fully prevent this enumeration. ... >I have a problem with restricting null user access to Windows XP. ...
    (Focus-Microsoft)
  • Re: Null session in Windows XP
    ... Null sessions can *always* be established to NT4, Windows 2000, and Windows ... would fully prevent this enumeration. ... >I have a problem with restricting null user access to Windows XP. ...
    (Focus-Microsoft)