Networking Forums

Networking Forums > Computer Networking > Windows Networking > Question on - Network Access: Do not allow anonymous enumeration of SAM accounts and shares

Reply
Thread Tools Display Modes

Question on - Network Access: Do not allow anonymous enumeration of SAM accounts and shares

 
 
Spin
Guest
Posts: n/a

 
      04-03-2008, 01:48 PM
Gurus,

How much of a security risk are these Windows security settings pose if they
are allowed? I am not looking for a security exposition, just a few quick
thoughts?

Network Access: Allow anonymous SID/Name translation
Network Access: Do not allow anonymous enumeration of SAM accounts
Network Access: Do not allow anonymous enumeration of SAM accounts and
shares

--
Spin







 
Reply With Quote
 
 
 
 
Roger Abell [MVP]
Guest
Posts: n/a

 
      04-10-2008, 04:44 AM
Only you can assess risk based on context of the machines.
Those settings only very rarely need to be set to allow these
things to anonymous. All your accounts can do those things
regardless of the settings.
So, based on context of machines you need to answer:
What risk is posed by allowing anyone that can connect via
the network the ability to discover my defined shares and
principals' (accounts, groups, joined computer) names, and
even the account and group SIDs that would not change when
these are renamed (such as done during response to penetration).
If your machines are not networked the risk is minimal, while
if live and naked on the internet then you would be needlessly
providing much info about your system (shares - where to
attempt logins distributed across multiple security event logs;
principals - what names to use; group - which are admins; etc.)
to anyone anywhere.
Roger


"Spin" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> Gurus,
>
> How much of a security risk are these Windows security settings pose if
> they are allowed? I am not looking for a security exposition, just a few
> quick thoughts?
>
> Network Access: Allow anonymous SID/Name translation
> Network Access: Do not allow anonymous enumeration of SAM accounts
> Network Access: Do not allow anonymous enumeration of SAM accounts and
> shares
>
> --
> Spin
>
>
>
>
>
>
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Access based enumeration Karen Wayland Windows Networking 1 02-12-2008 05:03 AM
Access Based Enumeration FletchInRaleigh Windows Networking 3 09-04-2006 10:48 PM
Access-based Enumeration doesn't work Drew Windows Networking 1 03-20-2006 07:30 PM
Network Access Only accounts Derz Wireless Networks 1 03-14-2006 08:10 PM
Anonymous Enumeration of accounts and shares Goo@tuxiecomputing.com Windows Networking 3 02-22-2005 06:54 PM



1 2 3 4 5 6 7 8 9 10 11