Re: W2K Guest Account and mitigation

From: Leythos (void_at_nowhere.com)
Date: 10/28/03


Date: Tue, 28 Oct 2003 01:36:02 GMT

In article <cAinb.79402$3f.69454
@twister01.bloor.is.net.cable.rogers.com>, dfox168@hotmail.com says...
> There is a technical requirement to enable guest account. Some applications
> were developed to use that account.
>
> "Leythos" <void@nowhere.com> wrote in message
> news:MPG.1a075b5f275ec80b989d93@news-server.columbus.rr.com...
> > In article <3f9d83fe_1@news1.prserv.net>, dfox168@hotmail.com says...
> > > If the guest account on a W2K member server must be enabled, what can
> one do
> > > to migitate the risk? Any pointers are appreciated.
> >
> > It doesn't need to be enabled - create another account with no password
> > and use it.

You've got to come up with another method - the risk to the network is
to great.

You "might" be able to secure it, but you are much better off having the
application "properly" coded.

-- 
--
spamfree999@rrohio.com
(Remove 999 to reply to me)