-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

After running a scan I found the hole listed below...
*********
It was possible to log into the remote host using a NULL session.
The concept of a NULL session is to provide a null username and
a null password, which grants the user the 'guest' access

To prevent null sessions, see MS KB Article Q143474 (NT 4.0) and
Q246261 (Windows 2000). 
Note that this won't completely disable null sessions, but will 
prevent them from connecting to IPC$
Please see


. All the smb tests will be done as ''/'' in domain 
CVE : CVE-2000-0222

**********
In researching the links, I'm not sure I understand the issue yet. 
In the message linked above it says that a connect can be made via a
null login.  However, it also says in the message that nothing can be
done from that point.
If they can't do anything, then why is this issue listed as High?  I
must be missing something.  
Please advise and thanks.

Chuck Fullerton
CISSP, CSS1, CCNP, CCNA, CCDA, CNA, A+
Network Engineer
Ficomp, Inc.
3015 Advance Lane
Colmar, PA  18915
Office 215-997-3879
Cell 610-780-7248
Pager 1-800-759-8352
TextPaging [EMAIL PROTECTED]
E-mail [EMAIL PROTECTED]
FICOMP, Inc. - Confidential and Proprietary



-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 7.0.3 for non-commercial use 

iQA/AwUBPjWRI7OJO5KNoAL1EQLKfACg/pfmDdkTg8E6r43g7WkGhOJSdpgAoN/A
x35QB1KHMAJ85pws1aGppisd
=fgaQ
-----END PGP SIGNATURE-----

Attachment: PGPexch.htm.asc
Description: PGPexch.htm.asc

Reply via email to