Re: Problem Disabling "Null Session" on W2K3



Do this

1. Go to Administrative Tools --> Local Security
Policy --> Local Policies --> Security Options.
Make sure the following two policies are enabled:

a. Network Access: Do not allow anonymous enumeration of SAM accounts: Enabled (Default)

b.Network Access: Do not allow anonymous enumeration of SAM accounts and shares: Enabled

Or this can also be accomplished using the following registry keys:

HKLM\System\CurrentControlSet\Control\Lsa\RestrictAnonymous=1 (This disallows enumeration of shares)
HKLM\System\CurrentControlSet\Control\Lsa\RestrictAnonymousSAM=1 (Default, not allowing enumeration of user accounts)

and then Reboot to make the changes take effect.

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: Access Denied Browsing Solution
    ... >I then went into Local Security Policy and set: ... >Network Access: Do not allow anonymous enumeration of SAM ... registry keys do, and if they are the same as the LSP settings. ...
    (microsoft.public.windowsxp.network_web)
  • RE: Cannot connect via Linked Server
    ... Network access: Do not allow anonymous enumeration of SAM accounts and shares: Disabled ... assistance from a Microsoft Support Professional through Microsoft Product ... Microsoft SQL Server Support Professional ...
    (microsoft.public.sqlserver.connect)
  • Re: LookupAccountName behavior dependent upon operating system of global catalog (GC)
    ... I checked the policy settings you noted earlier. ... Network access: Do not allow anonymous enumeration of SAM accounts - ENABLED ...
    (microsoft.public.platformsdk.security)
  • RE: Windows 95 - DSCLIENT
    ... your nt 4 pcs should be fine as well as any win 98 SECOND edition pcs. ... > B. Microsoft network client: ... > D. Network access: Do not allow anonymous enumeration of SAM accounts ...
    (microsoft.public.windows.server.migration)
  • Anonymous enumeration still enabled
    ... domain controller. ... I have applied all of the "network access" settings ... Do not allow anonymous enumeration of SAM ... Named pipes can be accessed anonymously|DISABLED ...
    (microsoft.public.security)