Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Disable Null Sessions

Reply
Thread Tools Display Modes

Disable Null Sessions

 
 
James
Guest
Posts: n/a

 
      01-12-2010
We had an audit and were told to disable null sessions on all of our
servers. I found that we could use group policy to accomplish this. I have
enabled the following settings on a test OU and moved a server to that OU.

Network access: Do not allow anonymous enumeration of SAM accounts
Enabled
Network access: Do not allow anonymous enumeration of SAM accounts and
shares Enabled

I was wondering the easiest way to verify that the null sessions have been
disabled? I downloaded a few applications that stated they would check this.
When I try to test I get the same results on my existing servers as I do on
the server that I put in the test OU with the GPO.


Thanks,
James


 
Reply With Quote
 
 
 
 
James
Guest
Posts: n/a

 
      01-12-2010
I noticed that when I scan the windows 2000 server that I have I can get
back the list of local users and groups. When I scan my windows 2003 member
servers I dont get anything back. When I scan my 2003 domain controllers I
get back a list of users and groups. What is the best way to apply settings
to the server to disable the ability to retrieve this information?




"James" <> wrote in message
news:...
> We had an audit and were told to disable null sessions on all of our
> servers. I found that we could use group policy to accomplish this. I have
> enabled the following settings on a test OU and moved a server to that OU.
>
> Network access: Do not allow anonymous enumeration of SAM accounts Enabled
> Network access: Do not allow anonymous enumeration of SAM accounts and
> shares Enabled
>
> I was wondering the easiest way to verify that the null sessions have been
> disabled? I downloaded a few applications that stated they would check
> this. When I try to test I get the same results on my existing servers as
> I do on the server that I put in the test OU with the GPO.
>
>
> Thanks,
> James
>



 
Reply With Quote
 
JASON ARCHER
Guest
Posts: n/a

 
      01-20-2010
What tools are you using. Many report false positive in that you can
connect to the IPC$ but are unable to enumerate any further information like
user accounts and domain machines.

So basically if you're tools state you have null sessions enabled but does
not retrieve account information then you're fixed.

Try Nessus tool as an example.

Rgds


On 12/01/2010 21:08, in article ,
"James" <> wrote:

> We had an audit and were told to disable null sessions on all of our
> servers. I found that we could use group policy to accomplish this. I have
> enabled the following settings on a test OU and moved a server to that OU.
>
> Network access: Do not allow anonymous enumeration of SAM accounts
> Enabled
> Network access: Do not allow anonymous enumeration of SAM accounts and
> shares Enabled
>
> I was wondering the easiest way to verify that the null sessions have been
> disabled? I downloaded a few applications that stated they would check this.
> When I try to test I get the same results on my existing servers as I do on
> the server that I put in the test OU with the GPO.
>
>
> Thanks,
> James
>
>


 
Reply With Quote
 
Dave Warren
Guest
Posts: n/a

 
      01-20-2010
In message <C77D0F07.162B%> JASON ARCHER
<> was claimed to have wrote:

>What tools are you using. Many report false positive in that you can
>connect to the IPC$ but are unable to enumerate any further information like
>user accounts and domain machines.
>
>So basically if you're tools state you have null sessions enabled but does
>not retrieve account information then you're fixed.
>
>Try Nessus tool as an example.


Are you suggesting Nessus tool as an example to retrieve information? Or
as an example of a tool that does it wrong?
 
Reply With Quote
 
JASON ARCHER
Guest
Posts: n/a

 
      01-21-2010
Little bit of both really, you can use the tool to identify if you have
'NULL' sessions that are insecure. If it returns users and machine info
then you have a problem, if it just returns the fact the NULL sessions are
enabled you're ok - I've never understood why they've never fixed it.


On 20/01/2010 20:44, in article ,
"Dave Warren" <dave-> wrote:

> In message <C77D0F07.162B%> JASON ARCHER
> <> was claimed to have wrote:
>
>> What tools are you using. Many report false positive in that you can
>> connect to the IPC$ but are unable to enumerate any further information like
>> user accounts and domain machines.
>>
>> So basically if you're tools state you have null sessions enabled but does
>> not retrieve account information then you're fixed.
>>
>> Try Nessus tool as an example.

>
> Are you suggesting Nessus tool as an example to retrieve information? Or
> as an example of a tool that does it wrong?


 
Reply With Quote
 
James
Guest
Posts: n/a

 
      02-03-2010
When scannin gmy singl ewindows 2000 member server I can get back a list of
usernames. When I scan my windows 2003 domain controllers i c an get back a
list of usernames. My 2003 member server do not give a list of usernames. I
am not sure how to prevent the 2000 server and the 2003 domain controllers
from providing the usernames. Any help would be great.

Thanks



"JASON ARCHER" <> wrote in message
news:C77E6312.1646%...
> Little bit of both really, you can use the tool to identify if you have
> 'NULL' sessions that are insecure. If it returns users and machine info
> then you have a problem, if it just returns the fact the NULL sessions are
> enabled you're ok - I've never understood why they've never fixed it.
>
>
> On 20/01/2010 20:44, in article
> ,
> "Dave Warren" <dave-> wrote:
>
>> In message <C77D0F07.162B%> JASON ARCHER
>> <> was claimed to have wrote:
>>
>>> What tools are you using. Many report false positive in that you can
>>> connect to the IPC$ but are unable to enumerate any further information
>>> like
>>> user accounts and domain machines.
>>>
>>> So basically if you're tools state you have null sessions enabled but
>>> does
>>> not retrieve account information then you're fixed.
>>>
>>> Try Nessus tool as an example.

>>
>> Are you suggesting Nessus tool as an example to retrieve information? Or
>> as an example of a tool that does it wrong?

>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Disable Windows Firewall Lanwench [MVP - Exchange] Windows Small Business Server 7 01-06-2010 11:45 PM
IE8 null sends "null" bug! Bengt Samuelsson Internet Explorer 2 12-31-2009 05:24 AM
IE8 null sends "null" bug! Bengt Samuelsson Internet Explorer 1 12-16-2009 04:35 PM
Re: can't disable netbios on XP or Vista John John - MVP Windows Vista Networking 0 11-01-2009 11:27 AM
ActiveSync 4.1, Calendar and "Processing" Dale Reeck ActiveSync 10 12-20-2005 12:44 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59