SMB share full access |
---|
Risk Level: | High | Check or Attack Name: All Access NetBIOS share found |
---|---|---|
Platforms: | Windows, Windows for Workgroups: 3.11, OS/2 | |
Description: | An SMB share was detected with no password required for full access. In some cases, an attacker can use these shares to gain access to the entire hard drive. It is common to find shares with all access enabled, since this is the default when the share is created. It is best to explicitly set the access control list on all shares. False Positives: In some cases, machines running Samba will show false positives. False Negatives: Applying the lm-fix patch will prevent you from accessing a Windows 95 share from a Windows NT machine. |
|
Remedy: | Remove the share. Windows: To remove a share, choose one of these options:
Other Operating Systems: Enable some form of access control as described in your OS documentation. |
|
References: |
Know Your Risks |