Question on - Network Access:  Do not allow anonymous enumeration of SAM accounts and shares

Question on - Network Access: Do not allow anonymous enumeration of SAM accounts and shares

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Question on - Network Access: Do not allow anonymous enumeration of SAM accounts and shares Spin 04-03-2008
Posted by Spin on April 3, 2008, 9:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Gurus,

How much of a security risk are these Windows security settings pose if they
are allowed? I am not looking for a security exposition, just a few quick
thoughts?

Network Access: Allow anonymous SID/Name translation
Network Access: Do not allow anonymous enumeration of SAM accounts
Network Access: Do not allow anonymous enumeration of SAM accounts and
shares

--
Spin








Posted by Roger Abell [MVP] on April 10, 2008, 12:44 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Only you can assess risk based on context of the machines.
Those settings only very rarely need to be set to allow these
things to anonymous. All your accounts can do those things
regardless of the settings.
So, based on context of machines you need to answer:
What risk is posed by allowing anyone that can connect via
the network the ability to discover my defined shares and
principals' (accounts, groups, joined computer) names, and
even the account and group SIDs that would not change when
these are renamed (such as done during response to penetration).
If your machines are not networked the risk is minimal, while
if live and naked on the internet then you would be needlessly
providing much info about your system (shares - where to
attempt logins distributed across multiple security event logs;
principals - what names to use; group - which are admins; etc.)
to anyone anywhere.
Roger


> Gurus,
>
> How much of a security risk are these Windows security settings pose if
> they are allowed? I am not looking for a security exposition, just a few
> quick thoughts?
>
> Network Access: Allow anonymous SID/Name translation
> Network Access: Do not allow anonymous enumeration of SAM accounts
> Network Access: Do not allow anonymous enumeration of SAM accounts and
> shares
>
> --
> Spin
>
>
>
>
>
>
>



Similar ThreadsPosted
Shares, Named Pipes, and Registry for Anonymous Remote Access February 23, 2007, 2:24 am
Anonymous enumeration March 2, 2006, 11:28 am
Anonymous enumeration still enabled December 2, 2005, 7:10 pm
Access to network shares January 25, 2007, 5:13 am
Read Only Access to ALL Shares On a Network December 12, 2005, 3:34 pm
network service accounts HKCU access December 21, 2005, 4:22 pm
Access Based Enumeration (ABE) August 18, 2006, 3:59 pm
Access Base Enumeration August 21, 2006, 3:08 pm
Tightening down shares on a network?? October 13, 2005, 2:02 pm
NETWORK and NETWORK SERVICE accounts April 21, 2006, 10:05 am

The site map in XML format XML site map

Contact Us | Privacy Policy