-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
Null sessions can allow a malicious user to enumerate the account database and thereby learn the name of the NT admin account as well as other accounts on the system. The NT admin account SID always ends with 500, no matter what it was renamed to. With this information in hand, the person could then attempt to retrieve the password hashes for cracking or just attempt to brute force the accounts. Follow the recommendations from Microsoft with regards to setting the RestrictAnonymous values in the registry. With these settings (do not use 0 or leave it undefined) you can stop enumeration, but not the connection to the null session. Hope this helps. Follow the link for more info: http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=%22null+sessions%22&btnG=Google+Search John Scott Chuck Fullerton wrote: | In researching the links, I'm not sure I understand the issue yet. | In the message linked above it says that a connect can be made via a | null login. However, it also says in the message that nothing can be | done from that point. | If they can't do anything, then why is this issue listed as High? I | must be missing something. | Please advise and thanks. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAj42pRsACgkQdDn2DhpCGPUlEwCg24jThA7oK6FmPJ5OC3DFPv/y Y9cAn344ZRkNoqUL4iyHmVe6z9MOzDi2 =KvOT -----END PGP SIGNATURE-----
