Re: A Hack Attack and IPC$

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 08/09/03


Date: Sat, 09 Aug 2003 18:50:13 GMT

On Sat, 09 Aug 2003 14:07:39 -0400, John Cesta spoketh

>
>My basic question: I know there is a way to delete the IPC$ share
>during a session but is there a way to delete the share so it does not
>create on reboot?
>
>Read the following if you need to know why this is important.
>
>Also, I hope this never happens to you.
>
>On M$ systems there are administrative shares that are created
>automatically. Some of these admin shares include: C$, D$, ADMIN$ and
>most importantly, IPC$ (a remote share).
>

Simple: change/set the value of "AutoShareServer" to zero in the
HKLM\System\CurrentControlSet\Services\LanManServer\Parameters

That'll disable all the admin shares.

If it's a workstations, the proper value is named "AutoShareWks".

Lars M. Hansen
http://www.hansenonline.net
(replace 'badnews' with 'news' in e-mail address)
"You're an angel with your wings broken"



Relevant Pages

  • Re: A Hack Attack and IPC$
    ... > during a session but is there a way to delete the share so it does not ... > On M$ systems there are administrative shares that are created ... Some of these admin shares include: ... > most importantly, IPC$. ...
    (comp.security.firewalls)
  • RE: Cannot keep hidden shares alive
    ... Regarding the missing IPC$ share, ... missing admin shares is malware that could be running on the computer, ... Start Registry Editor, and then locate the following registry ... Be aware that reinstalling TCP/IP or using the net share command ...
    (microsoft.public.win2000.file_system)
  • Re: Removing the IPC Share Automatically
    ... > Does Windows 2000 Server need the IPC Share to always be active? ... > I added a registry setting to remove "all administrative shares", ... > Hope this helps the people looking to remove there admin shares. ...
    (microsoft.public.windows.server.security)
  • Removing the IPC Share Automatically
    ... how to disable is so it will not come back after a reboot. ... I added a registry setting to remove "all administrative shares", now Im looking to remove IPC share. ... Hope this helps the people looking to remove there admin shares. ...
    (microsoft.public.windows.server.security)
  • What is nt authorityanonymous
    ... If you have any pre-Windows 2K/XP clients, ... IPC$ session) ... >some events generated by nt authority\anonymous logon. ...
    (microsoft.public.win2000.security)