Dear All, When I scanned my Windows 2003 domain controller with Nessus, it reported the following vulnerability:
------------------------------------------------------------------ Improperly configured LDAP servers will allow the directory BASE to be set to NULL. This allows information to be culled without any prior knowledge of the directory structure. Coupled with a NULL BIND, an anonymous user can query your LDAP server using a tool such as 'LdapMiner' Solution: Disable NULL BASE queries on your LDAP server ------------------------------------------------------------------- i googled but couldn't find how to disable NULL BASE queries in Windows 2000 and Windows 2003, Pls let me know on how to eliminate this vulnerability from Windows 2003 and 2000. thanx, joie -- ___________________________________________________________ Sign-up for Ads Free at Mail.com http://promo.mail.com/adsfreejump.htm _______________________________________________ Nessus mailing list [EMAIL PROTECTED] http://mail.nessus.org/mailman/listinfo/nessus
