Null Session Enumeration
i'm having issue 1 of domain controllers allowing null session enumeration , other not. i've checked registry settings on both , match, 1 can enumerate user information via null session.
in hkey_local_machine\system\currentcontrolset\control\lsa have following
restricanonymous = 1
restrictanonymoussam = 1
in hkey_local_machine\system\currentcontrolset\services\lanmanserver\parameters have following
restrictnullsessaccess = 1
i've diffed registry on both machines , can't find differences. other ideas on look?
thanks in advance.
hi jeremiahpeterson,
registry key values restrict null session below (applies : windows 2008, windows 2008 r2 , windows 2012/r2)
hkey\system\currentcontrolset\control\lsa:
restrictanonymous = 1
restrict anonymoussam = 1
everyoneincludesanonymous = 0
gpo settings:
computer configuration\policies\windows settings\security settings\local policies\securityoptions
enable:
network access: restrict anonymous access named pipes , shares
network access: not allow anonymous enumeration of sam accounts
network access: not allow anonymous enumeration of sam accounts , shares
network access: shares can accessed anonymously
disable:
network access: let permissions apply anonymous users
network access: allow anonymous sid/name translation
best regards,
anne
please remember mark replies answers if help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.
Windows Server > Network Infrastructure Servers
Comments
Post a Comment