Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NT Null Session Admin Name Vulnerability

Solution:
Establishing a null session in Windows NT opens a variety of flaws, but can be easily prevented. By setting the registry properly, anonymous connections are restricted. The registry setting for this is:

HKLM\System\CurrentControlSet\Control\Lsa
Name: RestrictAnonymous
Type: REG_DWORD
Value: 1

While this has not been tested against this specific code, It has been tested against other information gathering techniques that use a null connection to IPC$. With this registry setting enabled, you are still able to connect to IPC$, but cannot gain any further data about a domain.








 

Privacy Statement
Copyright 2009, SecurityFocus