Re: Default Shares

From: Roger Abell [MVP] (mvpNoSpam_at_asu.edu)
Date: 10/24/05


Date: Mon, 24 Oct 2005 07:51:52 -0700

Default shares require admin authN for access.
MS networking/filesharing is usually limited to specific
machines, or the "intranet", or is not bound to interfaces.
Removing the shares breaks only some things for admins,
but most work without the admin shares. However, it is
an open question what is really gained by removing them.
(obviously I assume that admin accounts are controlled,
both by long strong passcodes and as to their appropriate
usage).

"nospam" <bluetooth995@gmail.com> wrote in message
news:1130160678.673165.62990@g47g2000cwa.googlegroups.com...
> Hi all,
>
> Any secure practices would recommend you to
> disable all the windows default shares -C$..Admin$
>
> Of course, this is going to create problem for the system
> administrator - this limit their ability to
> manage the system with WMI, remote access,etc...
>
> So, if the admininstrator is having a strong password
> does it somehow mitigate the risk of having default shares?
>
> I would normally think defense in depth - though admin with
> strong password, but shnd still disable default shares
>
> Any comments?
>



Relevant Pages

  • Re: DC Admin question
    ... If someone needed to manage file shares, I would say, there are these X ... I would prefer no printers on DCs nor even queues, ... enhanced rights to is for some, likely good, reason. ... solutions to the unacceptible obvious one of giving admin. ...
    (microsoft.public.windows.server.security)
  • Re: Accessing SBS 2003 Shares with XP Home
    ... can see in server in network neighborhood. ... I have tried user password and admin password. ... access shares very easily. ... of the Admin account that was assigned to that share. ...
    (microsoft.public.windows.server.sbs)
  • Re: Defautl Hidden Shares
    ... the admin shares do slightly simplify life for that rogue person that must ... It's an even bigger risk if you left the local admin password blank... ... Those only allow access by an admin account. ...
    (microsoft.public.win2000.security)
  • use of compmgmt.msc to create/manage remote shares + ntfs permissions
    ... creation) only when they need to carry out those tasks. ... administrators group on these remote servers (they are server ... shares to connect on the fly to the remote server, ... obviously don't have admin rights to. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: Any way to remove ADMIN$ only?
    ... shares except for ADMIN$. ... modify it under the terms of the GNU GPL, as published by the Free Software ...
    (Focus-Microsoft)