Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Restrict Anonymous |
|---|---|
| Date: | Tue, 21 Sep 2004 17:10:18 -0400 |
It sounds like this has been set in group policy, most likely on the Domain Controllers OU. In GP, go to Computer Settings -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> Additional restrictions for anonymous connections (I'm working from memory here, so I might be off a bit) and choose the second option in the list, which should read something like "Do not allow enumeration of SAM accounts and shares". The reason that you're having problems with your XP clients only is because a setting of 2 for RA is no longer supported in XP or Win2k3. Instead, there are numerous other configuration options that allow you to achieve essentially the same result, but you need the XP/Win2K3 GP templates. Laura
-----Original Message----- From: Andrew Clelland [mailto:aclelland@rivermarkcu.org] Sent: Tuesday, September 21, 2004 12:03 PM To: 'focus-ms@securityfocus.com' Subject: Restrict Anonymous Good morning, I am curious about the Restrict Anonymous setting in Windows 2000 Server. Our DC is Windows 2000 and we have some servers with 2003 and half of our workstations are Windows XP. Every evening the restrict anonymous key changes to a DWORD value of 2 (allow users with explicit anonymous permission) and denies users on Windows XP the chance to change their expired password. Does anyone know of a way to force this setting to a DWORD value of 1 (restrict anonymous Users) or make Windows XP work with the DWORD value of 2? Thanks in advance for your insight and I look forward to the responses. ~Andy -------------------------------------------------------------- ------------- -------------------------------------------------------------- -------------
--------------------------------------------------------------------------- ---------------------------------------------------------------------------
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Application sniffer, Cerga, Skerdi (C3) |
|---|---|
| Next by Date: | Re: Application sniffer, rohit |
| Previous by Thread: | Restrict Anonymous, Andrew Clelland |
| Next by Thread: | Re: Restrict Anonymous, Thor |
| Indexes: | [Date] [Thread] [Top] [All Lists] |