Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
AuthorAll Replies

dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

reply to Daniel
Re: Windows File Sharing: Facing The Mystery

One more thing:

You forgot to mention that file-sharing requests are all subject to access control -- i.e., generally speaking, you need to log in before you can get access.

This is frequently overlooked in the "OMFG!!!! I have an open port!!!!!" view of the world. That doesn't mean that it's wise to expose TCP/445 to the greater Internet, but it does mean that there is layered protection.

In the obsolete Win9x implementation (and optionally in Samba), you have 'share level' authentication. A password is associated with the share, and if you know the password, you get access.

In Windows NT and most other modern implementations, you have 'user level' authentication. Accessors must know a username and password that is valid on the server, and (in implementations with decent authorization mechanisms), they get exactly the access that is due to the named user.

There is another wrinkle to user-level authentication, and that is 'guest access'. Windows may choose to allow unknown users to log in as user Guest for network accesses. This is generally a bad thing in my opinion. The Guest account is disabled by default in Win2000 and XP Pro, and you should only enable it if you understand the security ramifications. Rumour says it's on by default in XP Home.


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

said by dave See Profile:

One more thing:

You forgot to mention that file-sharing requests are all subject to access control -- i.e., generally speaking, you need to log in before you can get access.
True, but again, I wanted to limit my scope. Because once I mentioned that credentials were often required I'd have had to mention the fact that NULL Sessions are often possible in default configurations. It was a path I didn't want to take. A good idea though...
--
dmiessler.com - grep understanding knowledge
Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Monday, 09-Nov 18:09:47 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [63] VoIP Over 3G Still Not Working For iPhone
· [48] Verizon Keeps Swinging At AT&T
· [27] Bill Would Force ISPs To Block Financial Scams
· [15] Mediacom Hints At 50, 100 Mbps Speeds
· [11] Clearwire To Get Another $1.5 Billion
· [9] 15 States Have Now Gotten Broadband Mapping Money
· [4] AT&T Launching New 7.2 Mbps 3G Modem
Most people now reading
· Framed for child porn 151; by a PC virus [Security]
· Divorce advice... [General Questions]
· Blown out Ballasts [Home Repair & Improvement]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· My cat is reluctant to exercise. [General Questions]
· How in the world am I going to get into college? [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]
· A fishy CRTC tarriff filed by bell? [TekSavvy]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]