SMB enumation in Win2000/03

From: Stephen C. Gay (sgay_at_ellijay.com)
Date: 02/12/04

  • Next message: Ron Rollo: "How to secure access to private network files via IIS 6.0?"
    To: <security-basics@securityfocus.com>
    Date: Wed, 11 Feb 2004 21:28:10 -0500
    
    

    Hello,

    I am having difficulity locking down a couple of Windows Server 2003 domain
    controllers. I have locked down anonymous connections, per the Microsoft
    instructions and the servers are fully patched. Even with these measures, I
    can use tools like "enum" (Razor) or "hunt" (Foundstone) and harvest the
    user list from an unauthenicated workstation (directing the tools to a
    domain controller). I am no longer able to get the share list, just the
    users.

    The only way I have sucessfully stopped the vulnerability is by removal of
    File and Print Sharing on the 2 Doamin Controllers, but then I cannot add a
    workstation to the domain.

    If anyone could offer any suggestions I would be most grateful, as I'm
    running out of ideas.

    Thank you,
    Stephen Gay
    sgay@ellijay.com

    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection

    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.

    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.

    Download 30-day evaluation at:
    http://www.astaro.com/php/contact/securityfocus.php
    ----------------------------------------------------------------------------


  • Next message: Ron Rollo: "How to secure access to private network files via IIS 6.0?"

    Relevant Pages

    • Re: Exchange Server 2003 Active Directory Domain Controller recommendations
      ... See Q818080 for a hotfix applicable to Microsoft Windows Server 2003. ... > Exchange 2003 in our Windows Server 2003 AD environment. ... > controllers is the following: ... > It doesn't affect all domain controllers. ...
      (microsoft.public.exchange.design)
    • Re: Child Domains and how they relate to functional levels
      ... controllers, both running Windows Server 2000, and both are in Windows ... FOREST upgraded to Win2003 Forest Functional Level. ... but the two domain controllers in the child domain, ...
      (microsoft.public.windows.server.active_directory)
    • Moving FSMO roles
      ... We are in the process of migrating everything to Windows Server ... move it to our Windows Server 2003 Domain Controllers. ... The PDC role and RID Pool Manager is our new ... I would like to now move the FSMO roles from the 2000 boxes to 2003 ...
      (microsoft.public.windows.server.active_directory)
    • Re: Server Overview Question
      ... You can install/configure all these things on a single Windows Server 2003 ... > remote access, and backup. ... how do multiple domain controllers work and why would I want that? ...
      (microsoft.public.windows.server.setup)
    • Re: Security Log Help
      ... solution and verify that your domain controllers have the correct IP ... > Type: Failure ... An unexpected error occurred during logon ...
      (microsoft.public.win2000.security)