-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Null sessions can allow a malicious user to enumerate the account
database and thereby learn the name of the NT admin account as well as
other accounts on the system.  The NT admin account SID always ends with
500, no matter what it was renamed to.  With this information in hand,
the person could then attempt to retrieve the password hashes for
cracking or just attempt to brute force the accounts.  Follow the
recommendations from Microsoft with regards to setting the
RestrictAnonymous values in the registry.  With these settings (do not
use 0 or leave it undefined) you can stop enumeration, but not the
connection to the null session.  Hope this helps.

Follow the link for more info:
http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22null+sessions%22&btnG=Google+Search


John Scott

Chuck Fullerton wrote:
| In researching the links, I'm not sure I understand the issue yet.
| In the message linked above it says that a connect can be made via a
| null login.  However, it also says in the message that nothing can be
| done from that point.
| If they can't do anything, then why is this issue listed as High?  I
| must be missing something.
| Please advise and thanks.




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAj42pRsACgkQdDn2DhpCGPUlEwCg24jThA7oK6FmPJ5OC3DFPv/y
Y9cAn344ZRkNoqUL4iyHmVe6z9MOzDi2
=KvOT
-----END PGP SIGNATURE-----

Reply via email to