Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Anonymous Enumeration: a serious threat to Active Directory

 
Thread Tools Search this Thread
Old 11-08-2003, 09:58 PM   #1
Default Anonymous Enumeration: a serious threat to Active Directory


Hello

I'm trying to test Windows 2003 security. I've set up an Active Directory
and subjected it to non-firewalled access from internet to see how it would
survive.
Some policies i set up:

Network access: Allow anonymous SID/Name translation Disabled
Network access: Do not allow anonymous enumeration of SAM accounts
Enabled
Network access: Do not allow anonymous enumeration of SAM accounts and
shares Enabled
Network access: Let Everyone permissions apply to anonymous users
Disabled
Network access: Restrict anonymous access to Named Pipes and Shares
Enabled


BUT: to my shocking revolution I found out it could enumerate data from my
active directory despite this.

MY QUESTION: How can i protect my Active Directory from Anonymous
Enumeration?

The logentry is included:

Event Type: Success Audit
Event Source: Security
Event Category: Directory Service Access
Event ID: 565
Date: 2003-11-08
Time: 21:00:08
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: <My Computer>
Description:
Object Open:
Object Server: Security Account Manager
Object Type: SAM_SERVER
Object Name: CN=Server,CN=System,DC=<Mydomain>,DC=<MyD>,DC=<TLD >
Handle ID: 51442368
Operation ID: {0,1796199}
Process ID: 572
Process Name: C:\WINDOWS\system32\lsass.exe
Primary User Name: SALLY$
Primary Domain: <My Domain>
Primary Logon ID: (0x0,0x3E7)
Client User Name: ANONYMOUS LOGON
Client Domain: NT AUTHORITY
Client Logon ID: (0x0,0x1B6671)
Accesses: READ_CONTROL
InitializeServer
EnumerateDomains
Undefined Access (no effect) Bit 7

Privileges: -

Properties:
---
samServer

Access Mask: 0




Regards
Eric
(Remove the fast cat to mail me!)




Eric Anderson
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
windows Active directory santoo Software 0 05-16-2008 06:06 PM
Active Directory Password Policy Battousai General Help Related Topics 2 10-01-2007 04:11 PM
Active Directory Problem / Sync and Group Policy. keithalmli General Help Related Topics 0 08-11-2007 03:18 AM
IIS seetings for impersonation with basic authenticaion and Anonymous access sitaramig Software 0 06-03-2007 07:48 AM
windows 2000 server & active directory domains help fros A+ Certification 4 12-24-2003 12:06 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46