RE: Virus is getting domain account listing

From: Levinson, Karl (Karl.Levinson_at_dhs.gov)
Date: 05/10/04

  • Next message: Samuel Petreski: "RE: Virus is getting domain account listing"
    To: 'David Carlin' <djc6@cwru.edu>, focus-ms@securityfocus.com
    Date: Mon, 10 May 2004 11:42:11 -0400
    
    

    RestrictAnonymous=1 does not disable netbios null sessions or prevent
    enumeration of data. It just tries to reduce the amount of data detail that
    can be enumerated. Read the articles at www.securityfriday.com and download
    the free Getacct tool from that site to see what information is still
    available from your system anonymously.

    The default local administrator account always has the same SID number, so
    that it can trivially be accessed even if you rename it. One countermeasure
    commonly used is to disable the account and create your own. However, the
    list of users in the Administrators or Domain Admins group can still
    probably be enumerated as long as netbios null sessions are enabled.

    As you may know, for XP, there is a second registry value,
    RestrictAnonymousSam. Search www.google.com for "RestrictAnonymousSam" for
    information on how it works. In Windows 2000, as you may know there is also
    a value RestrictAnonymous=2 which does not exist in either NT, XP or 2003
    [but which is similar to RestrictAnonymous=1 plus RestrictAnonymousSAM=1 in
    XP and 2003]. This gets you closer to protecting your user lists. But you
    can't consider using these higher values until you get rid of NT, 9x and ME
    from your network, as well as some other legacy software considerations.
    The Windows 2000 Group Policy guide at www.nsa.gov/snac/ has some good
    information and links on the things that can break.

     

    > -----Original Message-----
    > From: David Carlin [mailto:djc6@cwru.edu]
    > Sent: Monday, May 10, 2004 9:11 AM
    > To: focus-ms@securityfocus.com
    > Subject: Virus is getting domain account listing
    >
    >
    > Hello,
    >
    > I work on a college campus and have been plagued for months by
    > something that is going through all of the accounts in my domains and
    > locking the accounts out by failed password attempts. I have
    > two PDCs
    > for two different domains, running NT 4.0 and clients running XP
    > scattered around campus in various subnets. I have setup an
    > ACL on my
    > cisco switch to block traffic to the PDCs except from these subnets,
    > but it doesn't help because there are machines in those subnets
    > administered by other people that continue to get "infected".
    >
    > My question is, how do I stop whatever this is from getting
    > my account
    > listing in the first place? I have run Microsoft baseline
    > analyzer, it
    > says I'm all good.. The free Nessus scanner doesn't report any
    > problems. I have all patches, RestrictAnonymous=1 is in the registry.
    >
    > I've renamed my admin account, this thing always picks up on it. It
    > knows which accounts are domain admins and attacks them more
    > aggressively. I've contacted the owners of the various machines
    > attacking, they never find any strange software, virus
    > scanners always
    > come up empty - even when done remotely over the
    > administrative shares.
    >
    > Any ideas how to protect my user list?

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Samuel Petreski: "RE: Virus is getting domain account listing"

    Relevant Pages

    • Re: NT AUTHORITYANONYMOUS LOGON
      ... Usually it's someone looking for shares, ... be account enumeration, which in your case would mean a hacker is sniffing ... Disable the guest account. ... >>> That server is connected to the Internet via a DSL line through a DSL ...
      (microsoft.public.win2000.security)
    • RE: Virus is getting domain account listing
      ... addresses can reach the NetBIOS ports on your servers; ... null session enumeration from normal activity [and since we're not even sure ... have not disabled the default local administrator account and created your ... even if you eventually disable Netbios null sessions. ...
      (Focus-Microsoft)
    • Re: ExMerge Works on Exchange Server but not on remote Workstation
      ... enumeration is an AD function. ... account (that has permissions to the stores) ExMerge works fine. ... But if I run ExMerge from my XP SP2 workstation (which has the Exchange ... Admin tools installed) and logged in as the same account, ...
      (microsoft.public.exchange2000.admin)
    • Re: Python from Wise Guys Viewpoint
      ... Joe Marshall writes: ... to the program, so if you enumerate all inputs, the enumeration would ... have to account for this. ... Matthias ...
      (comp.lang.lisp)
    • Re: How to display whole users sessions
      ... Usually what happens is a user has mapped drives to a resource from one ... To help try and track down where the account is getting locked out use ... sessions to find which users are connected to Active Directory. ...
      (microsoft.public.windows.server.active_directory)

  • Quantcast