Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > DNS Server > Security issues with LDAP NULL base connections on windows 2008

Reply
Thread Tools Display Modes

Security issues with LDAP NULL base connections on windows 2008

 
 
chris
Guest
Posts: n/a

 
      10-16-2009
Security issues with LDAP NULL base connections on windows 2008

http://www.nessus.org/plugins/index....ingle&id=10722

Solution : extract from above URL

If the remote LDAP server supports a version of the LDAP protocol
before v3, consider whether to disable NULL BASE queries on your LDAP
server.



Does Windows 2008 support LDAP Version 2 or LDAP Version 3 ? How do I go
about disabling it?



 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      10-16-2009

Hello chris,

By default, anonymous LDAP operations, except rootDSE searches and binds,
are not permitted on Windows 2003 domain controllers or higher.

See also here:
http://support.microsoft.com/kb/320528

Search for"Anonymous queries":
http://technet.microsoft.com/en-us/l...8WS.10%29.aspx



Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Security issues with LDAP NULL base connections on windows 2008
>
> http://www.nessus.org/plugins/index....ingle&id=10722
>
> Solution : extract from above URL
>
> If the remote LDAP server supports a version of the LDAP protocol
> before v3, consider whether to disable NULL BASE queries on your LDAP
> server.
>
> Does Windows 2008 support LDAP Version 2 or LDAP Version 3 ? How do I
> go about disabling it?
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Null.sys & Windows Away Mode System Issues MetalPirate Windows Vista Hardware 0 02-16-2009 09:22 AM
Re: Windows Server 2008 Knowledge Base Larry Struckmeyer [SBS-MVP] Windows Small Business Server 1 08-08-2008 01:59 PM
LDAP Null Base stadala Active Directory 5 06-18-2008 01:35 AM
LDAP query returns NULL data Drew Active Directory 2 12-07-2005 04:04 PM
LDAP Search Base Ana Active Directory 2 07-01-2004 03:34 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59