Re: Scanning for unsecure shared folders

From: Steven L Umbach (sumbach55_at_ameritech.net)
Date: 11/06/03


Date: Thu, 06 Nov 2003 02:29:33 GMT

Hi Jeff. There is a tool called LanGuard that you can try for free. It has a
lot of options and you may no want to scan all the options as it will slow
the scan down. You may also find the Microsoft Baseline Security Analyzer to
be of help in securing your machines and it can be used on remote machines.

http://www.gfi.com/languard/
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/
tools/mbsahome.asp
http://support.microsoft.com/default.aspx?kbid=320454

Keep in mind that in order to create shares a user must be a power user or
local administrator on their local machine. If you can have them be regular
users, then your network will be more secure. If they are local
administrators, you will have a lot of headaches and have much more
difficult time locking them down. For instance if a user has local
administrator powers, they can create a local machine account to log onto
and bypass any Group Policy user configuration and reconfigure the computer.

If their machines do not need to share resources and you do not need to
manage them remotely, then you can use Group Policy computer configuration
to disable the server service. If you want to remotely manage and they
should not be sharing resources you can control smb access via the user
right for "access this computer from the network" in security policy which
can be managed on a large scale with Group Policy. You can also replace the
everyone and users group on the access this computer from the network with
the authenticated users group for those domain members which will prevent
network access by a guest account if they have been enabled.

In a default installation, the everyone group may have full ntfs permissions
to the root/folder which should be reduced to read/list execute. Another
problem could be weak or no passwords. I would recommend implementing a
password policy that requires complex passwords that is configured at the
domain level.

Worms and viruses can also be an indication of improperly configured
firewall, inadequate virus scanning - particularly for emails, poor internet
securing, users connecting unathorized and unsecured computers such as their
laptops to YOUR network, computers/servers running unecessary services, and
a need to review patching with critical updates that may include SUS or
automatic updates. --- Steve

http://securityadmin.info/faq.asp#harden -- From the FAQ.
http://securityadmin.info/faq.asp#virustoc

"Jeff" <jeffpoling@yahoo.com> wrote in message
news:OuBZnl#oDHA.1884@TK2MSFTNGP09.phx.gbl...
> We have significant issues with viruses and worms because users create
> shared folders on their machines with Everyone group having the default
full
> control permissions. Is there a tool available to scan subnets for PCs
with
> unsecure shared folders? Is there a way to use Active Directory to prevent
> users from sharing folders?
>
> Thanks,
>
> Jeff
>
>



Relevant Pages

  • Home Networking- Fails?
    ... Please provide more configuration iformation: ... What operating systems are on the computers? ... Are all the machines configured with the same network ...
    (microsoft.public.windowsxp.network_web)
  • Re: VDQ : machine names??
    ... One other way that I've tried is to use system-config-network, and edit the configuration of eth0; but that seems to be little more than a pacifier. ... I want something that shows up in the prompts, and that I can use in ssh and scp, without having to look up IP numbers on the router all the time -- especially since not all LAN machines are on one floor. ... When your system connects to the network, it can tell the network which name it wants to be known as. ...
    (Fedora)
  • XP and SYSVOL Issues
    ... Windows cannot query for the list of Group Policy objects. ... see Help and Support Center at ... (The network path was not found. ... Does anyone have any idea why these machines would not be able to access the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How do I connect my PC and laptop using a crossover cable?
    ... Home on both machines in the default out-of-the-box configuration (simple ... make sure they are on the same network (go into the ... feasible solution is by a direct connection. ...
    (microsoft.public.windows.server.networking)
  • Force Group Policy to take presidents over the local policy
    ... We are having problems with Group Policy migrating down the network to ... It seems as if XP is using the Polices from the local machine ... machines only use the polices from the network. ...
    (microsoft.public.windows.group_policy)