WINS records deletion via SNMP |
---|
Risk Level: | Medium | Check or Attack Name: NT Delete Records |
---|---|---|
Platforms: | Windows NT | |
Description: | The Simple Network Management Protocol (SNMP) can remotely delete records from a WINS server, bypassing all Windows NT security mechanisms. WINS (Windows Internet Name Service) provides naming services in a fashion similar to the industry standard DNS (Domain Name Service). After a WINS client reboots, it will register with the WINS server. Until the client is registered, users of the client may not authenticate. Deleting the WINS records remotely via SNMP prevents authentication from proceeding, and user logins and screen unlocks will not work. |
|
Remedy: | Reboot the WINS client and disable or remove SNMP extension agents from this computer. If SNMP is required on a WINS server, choose a community name that is hard to guess, and configure SNMP to accept requests from specific hosts. To disable SNMP, follow these steps:
To change the SNMP community name and limit requests to specific hosts, follow these steps:
|
|
References: | BUGTRAQ Mailing List, "Rouland, Christopher J" <CRouland@EXAMNYC.lehman.com>, SNMP Insecurity, http://geek-girl.com/bugtraq/1997_4/0060.html |
Know Your Risks |