How can I restrict access to objects from Anonymous accounts?
It is possible to restrict the ability to list domain user names and
enumerate share names available to anonymous logon users (also known as NULL
session connections). If you feel this is a security risk Service Pack 3 for
Windows NT 4.0 introduces a new option to stop anonymous users listing users and
shares.
To enable this perform the following:
- Start the registry editor (regedit.exe)
- Move to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
- From the Edit menu select New - DWORD value and enter a name of
RestrictAnonymous if it does not already exist
- Double click the value and set to 1. Click OK
- Reboot the computer
After performing this change you should update your Emergency Repair Disk
using RDISK.EXE.
Security FAQ
Windows Privacy Tools - http//www.privacywindows.com
|