Guest Spin Posted April 3, 2008 Posted April 3, 2008 Gurus, How much of a security risk are these Windows security settings pose if they are allowed? I am not looking for a security exposition, just a few quick thoughts? Network Access: Allow anonymous SID/Name translation Network Access: Do not allow anonymous enumeration of SAM accounts Network Access: Do not allow anonymous enumeration of SAM accounts and shares -- Spin Quote
Guest Roger Abell [MVP] Posted April 10, 2008 Posted April 10, 2008 Only you can assess risk based on context of the machines. Those settings only very rarely need to be set to allow these things to anonymous. All your accounts can do those things regardless of the settings. So, based on context of machines you need to answer: What risk is posed by allowing anyone that can connect via the network the ability to discover my defined shares and principals' (accounts, groups, joined computer) names, and even the account and group SIDs that would not change when these are renamed (such as done during response to penetration). If your machines are not networked the risk is minimal, while if live and naked on the internet then you would be needlessly providing much info about your system (shares - where to attempt logins distributed across multiple security event logs; principals - what names to use; group - which are admins; etc.) to anyone anywhere. Roger "Spin" <Spin@invalid.com> wrote in message news:65k5gvF2efhc2U1@mid.individual.net...<span style="color:blue"> > Gurus, > > How much of a security risk are these Windows security settings pose if > they are allowed? I am not looking for a security exposition, just a few > quick thoughts? > > Network Access: Allow anonymous SID/Name translation > Network Access: Do not allow anonymous enumeration of SAM accounts > Network Access: Do not allow anonymous enumeration of SAM accounts and > shares > > -- > Spin > > > > > > > </span> Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.