Users enumerated through a null session |
---|
Risk Level: | Medium | Check or Attack Name: Users - null session |
---|---|---|
Platforms: | Windows NT | |
Description: | Users were enumerated through a null session. Account names may be acquired, providing the foundation for a brute force attack. |
|
Remedy: | Apply the latest Windows NT 4.0 Service Pack or Windows NT 4.0 Service Pack 2 (SP2) users must apply the sec fix, then regulate access to the NT registry. To apply the latest Windows NT 4.0 Service Pack, follow these steps:
—OR— To apply sec-fix, follow these steps:
—AND— To regulate access to the NT registry, follow these steps:
Value Name: RestrictAnonymous Data Type: REG_DWORD Value: 1. Warning: The winreg key will not be present if Service Pack 3 is not installed. Resetting the Registry entries is only effective after applying the patch and Service Pack 3. For more information, see Microsoft Knowledge Base Article Q155363. |
|
References: |
Know Your Risks |