Null session and Exchange2K

From: Jet Chan (yenjet.chan@eglobal.com.my)
Date: 06/20/02


From: "Jet Chan" <yenjet.chan@eglobal.com.my>
To: <focus-ms@securityfocus.com>
Date: Thu, 20 Jun 2002 18:38:42 +0800


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Greeting,

I wonder how many people got this error.
In the kb below, MS said Exchange2K cannot have
restrictanonymous=0x2,
otherwise it will blocks users from browsing the Global Address List.

http://support.microsoft.com/default.aspx?scid=kb;en-us;Q309622

So, is that means, an Exchange 2000 server cannot install SRP1 and
having restrictanonymous=0x2 ???
In this case, an Exchange 2000 server might vulnerable to Null
Session enumeration.
So is the only solution now is protect the server with firewall ?

regards,
.//Jet

-----BEGIN PGP SIGNATURE-----
Version: PGP 7.0.1
Comment: jchan@trusecure.com

iQA/AwUBPRGwr6JYwK+Y2D1BEQLR1ACg4El5R9RqQKsCDqvn2e9TmAtKpQ8AnAya
i/OEG0Axt58wezNzn+NIx5n9
=BOuz
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: Exchange Disaster Recovery Server
    ... The backup server is setup also in the lab so I ... >>> The Microsoft Exchange Server computer is not available. ... >>> Microsoft Exchange Server Information Store ...
    (microsoft.public.exchange2000.admin)
  • Exchange 2003 SP1 periodicaly losses connection to active directory for about 30 minutes
    ... We have active directory in two servers but the mail server fails to ... the promotion of the server to active directory the exchange was up. ... After a Domain Controller is promoted to a Global Catalog, ...
    (microsoft.public.exchange.connectivity)
  • Exchange 2003 SP1 periodicaly losses connection to active directory for about 30 minutes
    ... We have active directory in two servers but the mail server fails to ... the promotion of the server to active directory the exchange was up. ... After a Domain Controller is promoted to a Global Catalog, ...
    (microsoft.public.exchange.misc)
  • Re: LDAP Bind Unsuccessful
    ... We have a similar problem with Exchange 2003 and two DC servers 2003. ... After a Domain Controller is promoted to a Global Catalog, ... server that is designated to be a Global Catalog Server but did ...
    (microsoft.public.exchange2000.active.directory.integration)
  • Exchange Service Pack 1 Install fails
    ... I have a Small Business Server 2003 set up. ... Exchange SP1 resolves. ... before installing this Microsoft Exchange Server Service Pack. ...
    (microsoft.public.exchange.setup)

Quantcast