Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-21 Thread Andrew Bartlett
On Wed, 2002-11-20 at 07:51, Andrew Bartlett wrote: > On Wed, 2002-11-20 at 01:45, kirk johnson wrote: > > > > AB = andrew bartlett > > > > AB > Both options are only in Samba 3.0. Run 'testparm', before you > > > wonder why an option doesn't work. > > > > ah, now i understand what you mean

Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-19 Thread Andrew Bartlett
On Wed, 2002-11-20 at 01:45, kirk johnson wrote: > > AB = andrew bartlett > > AB > Both options are only in Samba 3.0. Run 'testparm', before you > > wonder why an option doesn't work. > > ah, now i understand what you meant by "samba HEAD". > > AB > It's an information leak - an unauthen

Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-19 Thread kirk johnson
AB = andrew bartlett AB > Both options are only in Samba 3.0. Run 'testparm', before you > wonder why an option doesn't work. ah, now i understand what you meant by "samba HEAD". AB > It's an information leak - an unauthenticated user can find out > a list of all users. Interestingly

Re: [Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-18 Thread Andrew Bartlett
On Tue, 2002-11-19 at 16:05, kirk johnson wrote: > > MM = M Maki (1 Oct 2002) > AB = Andrew Bartlett (2 Oct 2002) > > MM > I have a couple of Samba (2.0.7 & 2.2.0) servers I scanned with > > Nessus and they reported a security hole of "Possible to login > > to the remote host using a NUL

[Samba] IPC$ share accessible with arbitrary usernames/passwords

2002-11-18 Thread kirk johnson
MM = M Maki (1 Oct 2002) AB = Andrew Bartlett (2 Oct 2002) MM > I have a couple of Samba (2.0.7 & 2.2.0) servers I scanned with > Nessus and they reported a security hole of "Possible to login > to the remote host using a NULL session" I have a couple of NT > servers I disabled with