RE: Virus is getting domain account listing

From: Levinson, Karl (Karl.Levinson_at_dhs.gov)
Date: 05/11/04

  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #188"
    To: 'Corinna' <corinna@turbonet.com>, focus-ms@securityfocus.com
    Date: Tue, 11 May 2004 11:59:51 -0400
    
    

    On your 2003 servers, have you tried RestrictAnonymous=1 plus
    RestrictAnonymousSAM=1 ?

    As I said, my understanding is that RestrictAnonymous=2 is only a meaningful
    and valid value in Windows 2000. Assuming I'm correct on this, I would
    recommend you avoid using this value in XP, 2003 or NT, as it is untested
    and I have no idea what the end result might be on various OSes. It could
    be that this is the reason for your problem, who knows. I believe
    RestrictAnonymous=2 in Windows 2000 is similar or identical to using
    RestrictAnonymous=1 plus RestrictAnonymousSAM=1 in XP/2003.
     
    Also, make sure you haven't applied Group Policy templates that were
    designed for Windows 2000 onto Windows Server 2003.

    For Windows Server 2003, I'd recommend inspecting the available Group Policy
    options in the Group Policy MMC snap-in, and reading the various Microsoft
    documentation on what those settings do and where they should be set. For
    example, see the first link below, particularly the Group Policy settings
    that start with "Network access:"

    www.microsoft.com/resources/documentation/WindowsServ/2003/all/techref/en-us
    /w2k3tr_sepol_local_set.asp
    www.microsoft.com/technet/security

    -----Original Message-----
    From: Corinna [mailto:corinna@turbonet.com]
    Sent: Monday, May 10, 2004 6:01 PM
    To: focus-ms@securityfocus.com
    Subject: RE: Virus is getting domain account listing

    well, actually... this HKLM\System\CurrentControlSet\Control\LSA
    restrictanonymous=2, restrictanonymoussam=1

    the setting works only on our winxp, win2000, win2003 member machines...
    on our Win2003 AD domain controllers... one can still use null session to
    get our entire list of domain accounts.

    if anyone knows of any fix... please let me know.
    thanks!
     
    - corinna

    -----Original Message-----
    From: David Carlin [mailto:djc6@cwru.edu]
    Sent: Monday, May 10, 2004 10:30 AM
    To: focus-ms@securityfocus.com
    Subject: Re: Virus is getting domain account listing

    On May 10, 2004, at 11:42 AM, Levinson, Karl wrote:

    > RestrictAnonymous=1 does not disable netbios null sessions or prevent
    > enumeration of data. It just tries to reduce the amount of data
    > detail that can be enumerated. Read the articles at
    > www.securityfriday.com and download
    > the free Getacct tool from that site to see what information is still
    > available from your system anonymously.

    This was very helpful. Getacct does indeed show all my users, and
    conveniently marks which ones have Administrative privledges.

    > As you may know, for XP, there is a second registry value,
    > RestrictAnonymousSam. Search www.google.com for
    > "RestrictAnonymousSam" for information on how it works. In Windows
    > 2000, as you may know there is also
    > a value RestrictAnonymous=2 which does not exist in either NT, XP or
    > 2003
    > [but which is similar to RestrictAnonymous=1 plus
    > RestrictAnonymousSAM=1 in
    > XP and 2003]. This gets you closer to protecting your user lists.
    > But you
    > can't consider using these higher values until you get rid of NT, 9x
    > and ME
    > from your network, as well as some other legacy software
    > considerations.
    > The Windows 2000 Group Policy guide at www.nsa.gov/snac/ has some good
    > information and links on the things that can break.

    So basically, long term, wait for Active Directory - still waiting for
    campus network folks to implement this at the university level. We're
    not allowed to start our own AD on a per-department basis.

    There is not much I can do in the mean time to block whatever method
    getacct uses to gain access to the user list?

            -David

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Marc Fossi: "SecurityFocus Microsoft Newsletter #188"

    Relevant Pages

    • Windows Server 2003 upgrade Group Policy and DFS problems - SMB Signing
      ... domains to Windows Server 2003. ... Windows cannot query for the list of Group Policy objects. ... it is all to do with the fact that under Windows Server ... Because the 'Microsoft network server: ...
      (microsoft.public.win2000.group_policy)
    • Re: How do you all manage employee workstations? Looking for sugge
      ... 314886 Some Issues to Consider If Windows XP Users Have Roaming Profiles ... Folder Redirection is a User group policy. ... client computer will be saved in one server box. ...
      (microsoft.public.windows.server.sbs)
    • Re: How do you all manage employee workstations? Looking for suggestio
      ... 314886 Some Issues to Consider If Windows XP Users Have Roaming Profiles ... Folder Redirection is a User group policy. ... client computer will be saved in one server box. ... Microsoft CSS Online Newsgroup Support ...
      (microsoft.public.windows.server.sbs)
    • SecurityFocus Microsoft Newsletter #154
      ... MICROSOFT VULNERABILITY SUMMARY ... ISS RealSecure Server Sensor SSL Denial Of Service Vulnerabi... ... Roger Wilco Remote Server Side Buffer Overrun Vulnerability ... available for Microsoft Windows operating systems. ...
      (Focus-Microsoft)
    • RE: Can this command: aspnet_regiis.exe -i create issues?
      ... Please make sure Server Service is running on the SBS server. ... This issue may occur when a procedure to repair the Group Policy objects ... Windows Small Business Server 2003 computer has not been performed or was ...
      (microsoft.public.windows.server.sbs)

  • Quantcast