Dear All,

When I scanned my Windows 2003 domain controller with Nessus, it reported the 
following vulnerability:

------------------------------------------------------------------
Improperly configured LDAP servers will allow the directory BASE
to be set to NULL. This allows information to be
culled without any prior knowledge of the directory
structure. Coupled with a NULL BIND, an anonymous
user can query your LDAP server using a tool such
as 'LdapMiner'

Solution: Disable NULL BASE queries on your LDAP server
-------------------------------------------------------------------

i googled but couldn't find how to disable NULL BASE queries in Windows 2000 and 
Windows 2003,


Pls let me know on how to eliminate this vulnerability from Windows 2003 and 2000.

thanx,
joie
-- 
___________________________________________________________
Sign-up for Ads Free at Mail.com
http://promo.mail.com/adsfreejump.htm

_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to