1. Home
  2. Security Hardening
  3. DISA Windows Vista STIG V6R41
  4. Anonymous shares are not restricted. – RestrictAnonymousSAM

Anonymous shares are not restricted. – RestrictAnonymousSAM

Details

This is a Category 1 finding because it allows anonymous logon users (null session connections) to list all account names and enumerate all shared resources, thus providing a map of potential points to attack the system.

Solution

Configure the policy values for Computer Configuration -> Windows Settings -> Security Settings -> Local Policies -> Security Options -> ‘Network access- Do not allow anonymous enumeration of SAM accounts’ and ‘Network access- Do not allow anonymous enumeration of SAM accounts and shares’ to ‘Enabled’.

Supportive Information

The following resource is also helpful.

This security hardening control applies to the following category of controls within NIST 800-53: System and Communications Protection.This control applies to the following type of system Windows.

References

Source

Updated on July 16, 2022
Was this article helpful?

Related Articles