NNTP posting |
---|
Risk Level: | Low | Check or Attack Name: nntppost |
---|---|---|
Platforms: | Any | |
Description: | NNTP has been detected as running, and users can post to newsgroups without authorization. If the attacker has read access to the nntpd daemon, then your resources (and private company information, if your news server is for private newsgroups) may be obtained and used by unauthorized users. If posting access is allowed to the server, the NNTP server can be an access point for malicious users to post anonymous and possibly illegal information to the world from your computers. |
|
Remedy: | Disable the NNTP daemon or restrict access to newsgroups. Unix: To disable the NNTP daemon, follow these steps:
To restrict access:
Windows: To disable the NNTP service from Windows NT, follow these steps:
|
|
References: |
Know Your Risks |