Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Nessus: users

LDAP allows anonymous binds

 

 

Nessus users RSS feed   Index | Next | Previous | View Threaded


PBender at bannerbank

Nov 13, 2007, 9:30 AM

Post #1 of 3 (456 views)
Permalink
LDAP allows anonymous binds

Hi,
When Nessus was run against our two Domain Controllers, we received the following report:
Synopsis: It is possible to disclose LDAP information.

Description: Improperly configured LDAP servers will allow any user to connect to
the server and query it for information.

Solution: Disable NULL BIND on your LDAP server

Risk Factor : Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVE : CVE-1999-0385
BID : 503
Now when we look for a method to disable the null bind on out LDAP server, we are directed to a Microsoft update for MS Exchange 5.5. Since, we do use Exchange 5.5, I don't think it is this problem.
Can someone let me know where I can go to find a method(s) to disable the null bind on my Windows 2003 LDAP server(s)?
Thank you


P. J.


theall at tenablesecurity

Nov 13, 2007, 6:52 PM

Post #2 of 3 (436 views)
Permalink
Re: LDAP allows anonymous binds [In reply to]

On 11/13/07 12:30, PJ Bender wrote:

> When Nessus was run against our two Domain Controllers, we received
> the following report:
>
> *Synopsis*: It is possible to disclose LDAP information.
...
> *Solution*: Disable NULL BIND on your LDAP server
...
> I don’t think it is this problem.

FWIW, the plugin actually tries to query a server without authenticating
(ie, a "NULL BIND") and checks for a response. So it might be useful to
capture packets to/from the affected LDAP services and see what is being
returned.

> Can someone let me know where I can go to find a method(s) to disable
> the null bind on my Windows 2003 LDAP server(s)?

Have you searched Microsoft's site? For example: check out the
discussion of "dsHeuristics" in:

http://support.microsoft.com/kb/326690/

George
--
theall [at] tenablesecurity
_______________________________________________
Nessus mailing list
Nessus [at] list
http://mail.nessus.org/mailman/listinfo/nessus


Mike.Vasquez at cityofmesa

Nov 14, 2007, 7:35 AM

Post #3 of 3 (433 views)
Permalink
Re: LDAP allows anonymous binds [In reply to]

I did some research on the issue and the information for me was
inconclusive --

I found this post:
http://www.derkeiler.com/Newsgroups/microsoft.public.win2000.security/2005-10/0239.html

Date: Wed, 19 Oct 2005 12:07:35 -0400

You can't disable anonymous/NULL bind. LDAP V3 requires it for the
rootdse.
However, a null bind doesn't necessarily give you access to domain or
config
data. In fact, if you are running Windows Server 2003 AD you have to
specifically enable anonymous access on the ACLs to retrieve data

Here's a kb article about anonymous ldap operations:
http://support.microsoft.com/kb/326690
Anonymous LDAP operations to Active Directory are disabled on Windows
Server 2003 domain controllers

SUMMARY
By default, anonymous Lightweight Directory Access Protocol (LDAP)
operations to Active Directory, other than rootDSE searches and binds, are
not permitted in Microsoft Windows Server 2003.

There's another nice article here:
http://www.petri.co.il/anonymous_ldap_operations_in_windows_2003_ad.htm

Based on that information, I'm not convinced it's a great concern on
Win2k3. I would be interested in the impact of disabling it, per the
information provided. I'm a bit concerned about the possible fallout from
a change.

Thanks,

Mike




"George A. Theall" <theall [at] tenablesecurity>
Sent by: nessus-bounces [at] list
11/13/2007 07:52 PM

To
nessus [at] list
cc

Subject
Re: LDAP allows anonymous binds






On 11/13/07 12:30, PJ Bender wrote:

> When Nessus was run against our two Domain Controllers, we received
> the following report:
>
> *Synopsis*: It is possible to disclose LDAP information.
...
> *Solution*: Disable NULL BIND on your LDAP server
...
> I don?t think it is this problem.

FWIW, the plugin actually tries to query a server without authenticating
(ie, a "NULL BIND") and checks for a response. So it might be useful to
capture packets to/from the affected LDAP services and see what is being
returned.

> Can someone let me know where I can go to find a method(s) to disable
> the null bind on my Windows 2003 LDAP server(s)?

Have you searched Microsoft's site? For example: check out the
discussion of "dsHeuristics" in:

http://support.microsoft.com/kb/326690/

George
--
theall [at] tenablesecurity
_______________________________________________
Nessus mailing list
Nessus [at] list
http://mail.nessus.org/mailman/listinfo/nessus

Nessus users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.