Re: Explanation of Anonymous Named Pipes Security Policy



Will,

Read in the Wiindows Server 2003 Security guide.
There you will see that the two you mention are also controlled by the
setting to allow (or not) anonymous access to shares and named pipes,
and if I recall correctly, the guide recommends emptying the list of
shares for high sec environment.
The named pipes can be trimmed significantly for most machines.
The guide gives use information for these as

COMNAP - SNA session access
COMNODE - SNA session access
SQL\QUERY - SQL instance access
SPOOLSS - Spooler service
LLSRPC - License Logging service
Netlogon - Net Logon service
Lsarpc - LSA access
Samr - SAM access
browser - Computer Browser service

which is pretty fully informative except for maybe Samr, which is
the protocol for remote management of objects in the Sam.

"Will" <westes-usc@xxxxxxxxxxxxxx> wrote in message
news:%23qOVcEMxGHA.3264@xxxxxxxxxxxxxxxxxxxxxxx
Windows 2003 has a default local security policy that gives Anonymous
acccess to the following named pipes:

COMNAP
COMNODE
SQL\QUERY
SPOOLSS
netlogon
lsarpc
samr
browser

There is a separate security policy setting for Anonymous access to
shares:

COMCFG
CFS$

Is there any good documentation for what each of these is, and why Windows
2003 wants anonymous access to them? Which of these can safely be
removed
for:

- standalone server
- member server in a domain
- domain controller

--
Will




.



Relevant Pages

  • Re: NT4 -> Win2K3 question
    ... disable SMB signing for the Workstation or Server service on a domain ... Get Secure! ... The File Replication Service Event log test ... controller to the following destination domain ...
    (microsoft.public.windows.server.migration)
  • Re: installing certificate server issues
    ... How to remove data in Active Directory after an unsuccessful domain ... unsuccessful domain controller demotion. ... require you to reinstall Microsoft Windows 2000 Server, ... The attributes of the NTDS Settings object include data representing how the ...
    (microsoft.public.windows.server.active_directory)
  • Idiots Guide No 1 - How to use PuTTY for CrawlSS
    ... As stated in a previous thread and suggested on the Dungeon Crawl ... here is my first 'Idiots Guide'. ... Crawl Stone Soup on the akrasiac server, otherwise known as 'CAO', ... we are going to learn here how to use the 'PuTTY' terminal ...
    (rec.games.roguelike.misc)
  • Re: Mini-ITX PCs a the future of HA
    ... I can't see how you could ever leave a media server ... automation system so that bits can be distributed as required. ... theater controller scenario, ... What's connected to all the serial cards. ...
    (comp.home.automation)
  • Idiots Guide No 1 - How to Telnet
    ... As stated in a previous thread and suggested on the Dungeon Crawl ... here is my first 'Idiots Guide'. ... Crawl Sone Soup on the akrasiac server. ... e) encounter and kill/be killed by other players' ghosts ...
    (rec.games.roguelike.misc)