Re: disable NULL BIND on your LDAP server

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 10/19/05


Date: Wed, 19 Oct 2005 12:07:35 -0400

You can't disable anonymous/NULL bind. LDAP V3 requires it for the rootdse.
However, a null bind doesn't necessarily give you access to domain or config
data. In fact, if you are running Windows Server 2003 AD you have to
specifically enable anonymous access on the ACLs to retrieve data.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
Doug Fox wrote:
> Used NESSUS scanned a server.  It issued a warning saying that "ldap 
> (389/tcp) - improperly configured LDAP servers will allow any user to 
> connect to the server and query for information.  The solution is to 
> "disable NULL BIND on your LDAP server."
> 
> Did google many times, search results only show the 
> "suggestion/recommendation", but none of them show the steps to disable it.
> 
> Could someone please point me to a place where I can obtain the steps.
> 
> Thanks,
> 
> 
> 


Relevant Pages

  • Re: Query LDAP from Linux??
    ... the LDAP Java stuff was ... This means he will need a server name to bind too. ... He will need a port, if he wants to do a standard LDAP bind he will want 389. ...
    (microsoft.public.windows.server.active_directory)
  • Re: LDAP Lookup failure
    ... bind but LDP can, then that should clear ldap for you. ... ldap to bind to the server. ... When it fails can you also do a forward and reverse lookup of the host name ...
    (microsoft.public.windows.server.active_directory)
  • Bind DoS?
    ... Bind was compiled from ports, without threading, with gcc34 (from ... Machine A has a simple config of the following: ... queryperf -d list -s MACHINE_A_IP ... The server effectively dies, it can answer only a very little number of ...
    (freebsd-hackers)
  • Re: How to prevent LDAP simple bind?
    ... While you are using a program that uses ADSI to communicate to any ... the program cannot bind to the LDAP ... server by using the ADS_USE_SSL/ADS_USE_ENCRYPTION options in the ... SSL port number 636 when it makes a bind call to the LDAP server. ...
    (microsoft.public.win2000.active_directory)
  • Re: How to prevent LDAP simple bind?
    ... While you are using a program that uses ADSI to communicate to any ... the program cannot bind to the LDAP ... server by using the ADS_USE_SSL/ADS_USE_ENCRYPTION options in the ... SSL port number 636 when it makes a bind call to the LDAP server. ...
    (microsoft.public.windows.server.active_directory)