PC Review


Reply
Thread Tools Rate Thread

Anonymous Logon rights

 
 
rbs74@us.ibm.com
Guest
Posts: n/a
 
      22nd Apr 2004
Our group policy is configured so that the Everyone group does not include
the anonymous logon group. One of the side effects of this is that if a
user tries to log on and they are supposed to change their password, they
cannot.

We had orginally made the change because we were having mass lockouts from
anonymous users trying to brute force admin accounts.

We are debating giving explicit permissions to anonymous login for the
"access this computer from the network". If we still have the "Do not
allow anonymous enumeration of SAM accounts" and "do not allow
anonymous/SID translation" options enabled, will this change pose a
serious security threat?
 
Reply With Quote
 
 
 
 
Steven L Umbach
Guest
Posts: n/a
 
      23rd Apr 2004
What is network makeup? Are you using downlevel clients? The cure for attacks on the admin account is a firewall unless it is happening from the lan in which case you should know what lan computer it is originating from. Make sure that you do not have netbios/smb 445 ports exposed to the internet. You can go to http://scan.sygatetech.com/ to do a quick assesment of your network vulnerability. The link below explains those anonymous settings you are talking about and when and when not to use them. --- Steve

http://www.microsoft.com/technet/Sec...g/sgch03..mspx
http://support.microsoft.com/default...b;en-us;823659
<(E-Mail Removed)> wrote in message news:COThc.54290$(E-Mail Removed)...

Our group policy is configured so that the Everyone group does not include the anonymous logon group. One of the side effects of this is that if a user tries to log on and they are supposed to change their password, they cannot.

We had orginally made the change because we were having mass lockouts from anonymous users trying to brute force admin accounts.

We are debating giving explicit permissions to anonymous login for the "access this computer from the network". If we still have the "Do not allow anonymous enumeration of SAM accounts" and "do not allow anonymous/SID translation" options enabled, will this change pose a serious security threat?
 
Reply With Quote
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Event ID 538 Logon Type 3 NT AUTHORITY/ANONYMOUS LOGON =?Utf-8?B?Ly5keg==?= Microsoft Windows 2000 Security 15 1st Jul 2006 03:06 AM
Why Anonymous Logon Clark Windows XP Security 1 26th Jul 2005 04:25 PM
Anonymous Logon Preacher Man Microsoft Windows 2000 Networking 3 23rd Mar 2005 08:47 PM
anonymous logon gazebo Microsoft Windows 2000 Security 0 6th Nov 2003 04:55 AM
anonymous logon Sandy Ryan Microsoft Windows 2000 Security 0 23rd Oct 2003 09:38 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 09:57 AM.