Home > Enterprise Desktop Tips > > How to prevent null session attacks
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


How to prevent null session attacks


Kevin Beaver
10.07.2004
Rating: -3.86- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In part one of this two-part series, Windows Security Threats site expert Kevin Beaver explained where and why null session vulnerabilities continue to run rampant. Part two below will discuss how you can prevent null session attacks.


In my first article, I described how a null session vulnerability attack occurs and who is most vulnerable. Now the question is, how can you protect your systems?

There is a solution
One quick fix is to upgrade your desktops to Windows XP and your servers to Windows Server 2003. This is not completely foolproof because these systems can have their security policies or registry settings misconfigured to permit this exploit.

For Windows NT 4.0 systems running Service Pack 3 and higher, you can create the \\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\RestrictAnonymous key in the registry and set it to a value of 1. This will prevent certain anonymous connections, but not all of them. The only true fix for the null session vulnerability on Windows NT is a good intrusion prevention system (IPS) -- or better yet upgrade to Windows XP or Server 2003.

For Windows 2000 systems, you can use RestrictAnonymous=2 in the registry or set the "Additional restrictions for anonymous connections" in the Windows security policy to "No access without explicit anonymous permissions."

Your best option is to simply block SMB communications by limiting traffic on TCP ports 139 and 445 (excluding NT which doesn't use 445) to trusted networks. I know it seems painfully obvious, but people still have unprotected Windows systems out there for the taking. A basic firewall and host-based IPS can do wonders for this.

Do it yourself
I encourage you to check this out yourself on your own Windows systems -- especially the critical systems such as servers and administrator stations. By creating null session connections and using the tools listed above and even one of my favorite tools -- SuperScan by Foundstone -- you can test for this serious vulnerability and fix it before the bad guys point it out for you.

Luckily, Microsoft is heading down the right path by changing default Windows security settings to help prevent the null session vulnerability from being exploited. But you'd still need to periodically test your systems, even if they've been hardened, to make sure they can't be exploited. You never know when the bad guys wilkl pull out their old tricks to try and take your network down.

Click to return to part one.


About the author
Kevin Beaver is founder and principal consultant of Atlanta-based Principle Logic LLC, as well as a resident expert on SearchWindowsSecurity.com. He specializes in information security assessments and incident response and is the author of the new book "Hacking for dummies" by John Wiley and Sons. Kevin can be reached at kbeaver@principlelogic.com or ask him a question on Windows security threats today.

For More Information

Get Five steps to controlling network access

Learn eight ways to protect Windows from perimeter threats.

Ask expert Kevin Beaver your Windows security threats questions.



Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network intrusion detection and prevention and malware removal
20 days to a more secure enterprise
Improvements to offline file synchronization in Windows 7
Underlying causes of inconsistent patch management
Windows security tools for the busy desktop administrator
Check IT List: Five steps for rootkit detection
Top Windows client security tools for end users
Hacking Exposed Windows: Windows security features and tools
Tools for virus removal and detection
Windows security testing: Five tips for the summer
Buffer overflows can be prevented by GS cookies

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts