Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

Re: Windows File Sharing: Facing The Mystery

One more thing:

You forgot to mention that file-sharing requests are all subject to access control -- i.e., generally speaking, you need to log in before you can get access.

This is frequently overlooked in the "OMFG!!!! I have an open port!!!!!" view of the world. That doesn't mean that it's wise to expose TCP/445 to the greater Internet, but it does mean that there is layered protection.

In the obsolete Win9x implementation (and optionally in Samba), you have 'share level' authentication. A password is associated with the share, and if you know the password, you get access.

In Windows NT and most other modern implementations, you have 'user level' authentication. Accessors must know a username and password that is valid on the server, and (in implementations with decent authorization mechanisms), they get exactly the access that is due to the named user.

There is another wrinkle to user-level authentication, and that is 'guest access'. Windows may choose to allow unknown users to log in as user Guest for network accesses. This is generally a bad thing in my opinion. The Guest account is disabled by default in Win2000 and XP Pro, and you should only enable it if you understand the security ramifications. Rumour says it's on by default in XP Home.

Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

Re: Windows File Sharing: Facing The Mystery

said by dave See Profile:

One more thing:

You forgot to mention that file-sharing requests are all subject to access control -- i.e., generally speaking, you need to log in before you can get access.
True, but again, I wanted to limit my scope. Because once I mentioned that credentials were often required I'd have had to mention the fact that NULL Sessions are often possible in default configurations. It was a path I didn't want to take. A good idea though...
--
dmiessler.com - grep understanding knowledge
Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Wednesday, 02-Dec 17:29:54 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [159] Comcast Releasing Promised Usage Meter
· [89] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [78] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [61] Broadband Killed The Game Console
· [54] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [38] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
Most people now reading
· MS admits Windows Updates principally created to annoy [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· A little freaky, not sure if its legit. [Spam, Scam and Phishbusters]
· Am I the only one that loves to work in IT? [No, I Will Not Fix Your #@$!! Computer]
· Windows 7 boot manager editing questions [Microsoft Help]
· [Business] how to bridge a smc 8014 business class modem [Comcast HSI]
· Captchas get smarter [Security]
· UBB round 2 at the CRTC [Canadian Broadband]
· DK Weapon Upgrade [World of Warcraft]
· Quality/longevity of 15A 120V receptacles [Home Repair & Improvement]