OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Meidling, Keith (Keith.MeidlingCWUSA.COM)
Date: Sat Sep 29 2001 - 09:54:37 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Usually the guest account doesn't have a password. So I went through my
    machines, changed the password, and then disabled it. This way if the guest
    account gets re-enabled for some reason, it's not as much of a security
    risk. :-)

    -----Original Message-----
    From: Thomas Shokes [mailto:tshokesintelesis.com]
    Sent: Thursday, September 27, 2001 11:02 AM
    To: 'Evan Mann'; 'focus-mssecurityfocus.com'
    Subject: RE: Open Guest Share question

    Disable your "Guest" account on those servers. Then the "Guest" user can't
    acces your system at all.

    -----Original Message-----
    From: Evan Mann [mailto:emannquestinc.org]
    Sent: Wednesday, September 26, 2001 1:22 PM
    To: 'focus-mssecurityfocus.com'
    Subject: Open Guest Share question

    I ran the free version of eEye's Nimda scanner and it came back with "Open
    Guest Share" on all of my Servers, both WinNT 4.0 SP6a and Windows 2000.

    Now, all of these machines are patched and none are actually infected. So
    what is this "Opne Guest Share" then? How do I remedy it as a security
    hole?

    Evan Mann