NetBIOS share full access by Everyone group |
---|
Risk Level: | Medium | Check or Attack Name: All Access NetBIOS share - Everyone |
---|---|---|
Platforms: | Windows NT, Samba, Windows 95 | |
Description: | A NetBIOS share has been detected with no access control. This misconfiguration can allow access to the entire hard drive on unpatched versions of Windows NT. In Windows NT, it is common to find shares with all access enabled, since this is the default when the share is created. It is best to explicitly set the access control list on shares. If this vulnerability was detected on a version of Windows NT prior to Service Pack 3 (SP3), an attacker can use shares to cause the machine to crash. |
|
Remedy: | Set the permissions explicitly or remove the share.
—OR— Windows: To remove a share, choose one of these options:
Other Operating Systems: Enable some form of access control as described in your OS documentation. |
|
References: | Microsoft Knowledge Base Article Q128079, Updated Drivers for File and Printer Sharing Security, http://support.microsoft.com/support/kb/articles/q128/0/79.asp |
Know Your Risks |