On Wed, 2003-12-17 at 13:40, Jonas Carlsson wrote:
>    James R. Trater wrote:
>  > Try setting:
>  > guestaccount = NULL
>  > and
>  > restrict anonymous = yes
>  > in you smb.conf
>  > I had the same problem, and this solved it for me.
> 
> Just for the records; it really did the trick.
> Nessus reports nothing now!

Also for the record, we strongly recommend against this.  Instead, run
Samba 3.0 and set 'guest account = nobody', if nobody is a valid user,
and set 'restrict anonymous = 2' if you are not running a PDC, and not
performing any browsing services.

'restrict anonymous' had no security benifit in Samba 2.2, but may have
fooled the scanner.

Andrew Bartlett

-- 
Andrew Bartlett                                 [EMAIL PROTECTED]
Manager, Authentication Subsystems, Samba Team  [EMAIL PROTECTED]
Student Network Administrator, Hawker College   [EMAIL PROTECTED]
http://samba.org     http://build.samba.org     http://hawkerc.net

Attachment: signature.asc
Description: This is a digitally signed message part

-- 
To unsubscribe from this list go to the following URL and read the
instructions:  http://lists.samba.org/mailman/listinfo/samba

Reply via email to