Security Basics mailing list archives

Re: Problem Disabling "Null Session" on W2K3


From: Alexey Vesnin <ss666 () bsd mirknigi ru>
Date: Wed, 15 Nov 2006 11:39:42 +0300

eneko.astorkiza () ieuskadi com wrote:
Hi all,

Firstly excuse my english, i'm spanish.

I'm trying to secure some AD servers and i have a problem.

I scan then (w2k3 AD Servers) with Retina and it says that i have "Null Session" enabled, so it shows all the domain users. 
(I'm doing with a machine out of the domain)

The problem is that if i look at the RestrictAnonymous and RestrictAnonymousSAM registry values, they are ok :-?

Someone knows why i can enumerate the domain users ???

I have also use SuperScan and the same happens.


Un saludo

          Eneko

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------

Try Outpost Firewall Pro - or something similar. It's a well-tuned windows firewall, and you can disable the session establishment everywhere except the IP's needed.

Alexey Vesnin

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence in Information Security. Our program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Using interactive e-Learning technology, you can earn this esteemed degree, without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------


Current thread: