Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-21 Thread Andrew Bartlett
On Wed, 2002-11-20 at 07:51, Andrew Bartlett wrote: On Wed, 2002-11-20 at 01:45, kirk johnson wrote: AB = andrew bartlett AB Both options are only in Samba 3.0. Run 'testparm', before you wonder why an option doesn't work. ah, now i understand what you meant by samba HEAD.

Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-19 Thread kirk johnson
AB = andrew bartlett AB Both options are only in Samba 3.0. Run 'testparm', before you wonder why an option doesn't work. ah, now i understand what you meant by samba HEAD. AB It's an information leak - an unauthenticated user can find out a list of all users. Interestingly,

Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-19 Thread Andrew Bartlett
On Wed, 2002-11-20 at 01:45, kirk johnson wrote: AB = andrew bartlett AB Both options are only in Samba 3.0. Run 'testparm', before you wonder why an option doesn't work. ah, now i understand what you meant by samba HEAD. AB It's an information leak - an unauthenticated user

Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-18 Thread Andrew Bartlett
On Tue, 2002-11-19 at 16:05, kirk johnson wrote: MM = M Maki (1 Oct 2002) AB = Andrew Bartlett (2 Oct 2002) MM I have a couple of Samba (2.0.7 2.2.0) servers I scanned with Nessus and they reported a security hole of Possible to login to the remote host using a NULL session I