Security Basics mailing list archives

Re: Problem Disabling "Null Session" on W2K3


From: Ansgar -59cobalt- Wiechers <bugtraq () planetcobalt net>
Date: Wed, 15 Nov 2006 23:11:22 +0100

On 2006-11-15 Alexey Vesnin wrote:
eneko.astorkiza () ieuskadi com wrote:
I'm trying to secure some AD servers and i have a problem.

I scan then (w2k3 AD Servers) with Retina and it says that i have
"Null Session" enabled, so it shows all the domain users. (I'm doing
with a machine out of the domain)

The problem is that if i look at the RestrictAnonymous and
RestrictAnonymousSAM registry values, they are ok :-?

Someone knows why i can enumerate the domain users ???

I have also use SuperScan and the same happens.

Try Outpost Firewall Pro - or something similar. It's a well-tuned
windows firewall, and you can disable the session establishment
everywhere except the IP's needed.

Outpost (or any other personal firewall) does NOT solve the problem at
hand. The appropriate measure - as has already been suggested - is to
disable null sessions through the respective group policy.

Regards
Ansgar Wiechers
-- 
"All vulnerabilities deserve a public fear period prior to patches
becoming available."
--Jason Coombs on Bugtraq

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence 
in Information Security. Our program offers unparalleled Infosec management 
education and the case study affords you unmatched consulting experience. 
Using interactive e-Learning technology, you can earn this esteemed degree, 
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: