UNSOLVED

greinerr

updated

14 years ago

G

greinerr

4 Posts

0

3738

June 4th, 2012 13:00

RestrictAnonymous Setting

A NESSUS scan has identified the following vulnerability on our Celerra. 

2CN56210 - "Microsoft Windows SMB LsaQueryInformationPolicy Function SID Enumeration Without Credentials."

"You can prevent anonymous lookups of the host SID by setting the 'RestrictAnonymous' registry setting to an appropriate value"

Is there a similar setting that can be changed on the Celerra?


Thanks


Rich

  • 1578

    0

    Posted June 11th, 2012 09:00

    Hi Rich ,

    can you please let me know where are you seeing these messages ?

    Thanks

    Vanitha

  • OmerGuney

    1 Message

    1578

    0

    Posted June 12th, 2012 08:00

    Rich, Vanitha, hi,

    I also have the same issue and more.

    When a Nessus scan is performed against either Celerra NS-G2 or Celerra NS-120, the following vulnerability is reported.

    http://www.nessus.org/plugins/index.php?view=single&id=56210

    Additionally, I get the the following vulnerability as well.

    http://www.nessus.org/plugins/index.php?view=single&id=12209

    What is the configuration that should be implemented on both devices in order to prevent these vulnerabilities from being reported?

    Thanks,

    Omer.

  • SAMEERK1

    296 Posts

    1578

    0

    Posted June 13th, 2012 04:00

    Hi,

    try to configure the registry settings for cifs server as mentioned in the MS article :

    http://technet.microsoft.com/en-us/library/bb418944.aspx

    Sameer Kulkarni

  • 1578

    0

    Posted October 17th, 2012 01:00

    Hi,

    it's simply not possible to set those registry settings as mentioned by Microsoft. Is there any other way to close this security leak?

    Thanks

    Mathias

  • tmhudg1

    20 Posts

    1578

    0

    Posted December 10th, 2012 13:00

    I'm running into this issue as well. A security scan of the customer environment identified this as a vulnerability.

    Any help on how to remediate this would be greatly appreciated.

    Thanks,

    Tom

  • christopher_ime

    6 Operator

    •

    1962 Posts

    1578

    0

    Posted December 10th, 2012 23:00

    Review the following KB article which I believe is relevant and what the scanner is picking up on.

    emc178968: "How to disable the CIFS nullSession parameter"

    I will mention though that I don't have any experience with this specific setting, so if further clarification than what is in the document is needed I would follow-up with support and maybe let's see if anyone else has any comments and responds here.

  • tmhudg1

    20 Posts

    1578

    0

    Posted December 11th, 2012 06:00

    Christopher,

    This is exactly what I was looking for! Thanks very much!

    Tom