Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Windows File Sharing: Facing The Mystery
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
turning off Windows FW when running ZAP »
« This one is starting to wear me out.....  
AuthorAll Replies


Daniel
Premium,MVM
join:2000-06-26
Pleasanton, CA
clubs:

reply to dave
Re: Windows File Sharing: Facing The Mystery

said by dave See Profile:

One more thing:

You forgot to mention that file-sharing requests are all subject to access control -- i.e., generally speaking, you need to log in before you can get access.
True, but again, I wanted to limit my scope. Because once I mentioned that credentials were often required I'd have had to mention the fact that NULL Sessions are often possible in default configurations. It was a path I didn't want to take. A good idea though...
--
dmiessler.com - grep understanding knowledge

dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

reply to Daniel
One more thing:

You forgot to mention that file-sharing requests are all subject to access control -- i.e., generally speaking, you need to log in before you can get access.

This is frequently overlooked in the "OMFG!!!! I have an open port!!!!!" view of the world. That doesn't mean that it's wise to expose TCP/445 to the greater Internet, but it does mean that there is layered protection.

In the obsolete Win9x implementation (and optionally in Samba), you have 'share level' authentication. A password is associated with the share, and if you know the password, you get access.

In Windows NT and most other modern implementations, you have 'user level' authentication. Accessors must know a username and password that is valid on the server, and (in implementations with decent authorization mechanisms), they get exactly the access that is due to the named user.

There is another wrinkle to user-level authentication, and that is 'guest access'. Windows may choose to allow unknown users to log in as user Guest for network accesses. This is generally a bad thing in my opinion. The Guest account is disabled by default in Win2000 and XP Pro, and you should only enable it if you understand the security ramifications. Rumour says it's on by default in XP Home.
Forums » Up and Running » Security » Securityturning off Windows FW when running ZAP »
« This one is starting to wear me out.....  


Wednesday, 02-Dec 23:07:27 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [161] Comcast Releasing Promised Usage Meter
· [94] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [79] Latest Consumer Reports Survey Not Kind To AT&T
· [70] Baltimore To Ban Lazy Cable Installs
· [62] Broadband Killed The Game Console
· [55] Rogers Unveils The ISP Dream Model
· [46] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [39] AT&T, Verizon Drop 3G Ad Dispute
· [38] Charter Exits Chapter 11
Most people now reading
· False positive in Avast! or is it real? [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Microsoft actively urges IE 6 users to upgrade [Security]
· Ooma changing features [VOIP Tech Chat]
· Just got new pc with Windows 7 Premium 64 bit..... [Security]
· Poll: Have you ever been charged an overage fee since ... [TekSavvy]
· [WIN7] When exactly should you flash bios when installing new OS [Microsoft Help]
· [Poll] Canadian Chat. [Canadian Chat]
· wtf is up with the shitty internet again [Suddenlink]