Re: Problem Disabling "Null Session" on W2K3
- From: Ansgar -59cobalt- Wiechers <bugtraq@xxxxxxxxxxxxxxxx>
- Date: Wed, 15 Nov 2006 23:11:22 +0100
On 2006-11-15 Alexey Vesnin wrote:
eneko.astorkiza@xxxxxxxxxxxx wrote:
I'm trying to secure some AD servers and i have a problem.
I scan then (w2k3 AD Servers) with Retina and it says that i have
"Null Session" enabled, so it shows all the domain users. (I'm doing
with a machine out of the domain)
The problem is that if i look at the RestrictAnonymous and
RestrictAnonymousSAM registry values, they are ok :-?
Someone knows why i can enumerate the domain users ???
I have also use SuperScan and the same happens.
Try Outpost Firewall Pro - or something similar. It's a well-tuned
windows firewall, and you can disable the session establishment
everywhere except the IP's needed.
Outpost (or any other personal firewall) does NOT solve the problem at
hand. The appropriate measure - as has already been suggested - is to
disable null sessions through the respective group policy.
Regards
Ansgar Wiechers
--
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq
---------------------------------------------------------------------------
This list is sponsored by: Norwich University
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.
http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------
- References:
- Problem Disabling "Null Session" on W2K3
- From: eneko . astorkiza
- Re: Problem Disabling "Null Session" on W2K3
- From: Alexey Vesnin
- Problem Disabling "Null Session" on W2K3
- Prev by Date: Re: Small business IT security
- Next by Date: RE: Log Analysis
- Previous by thread: Re: Problem Disabling "Null Session" on W2K3
- Next by thread: RE: Problem Disabling "Null Session" on W2K3
- Index(es):
Relevant Pages
|