Important Notice: Our web hosting provider recently started charging us for additional visits, which was unexpected. In response, we're seeking donations. Depending on the situation, we may explore different monetization options for our Community and Expert Contributors. It's crucial to provide more returns for their expertise and offer more Expert Validated Answers or AI Validated Answers. Learn more about our hosting issue here.

Are there any especially interesting keys to watch?

0
Posted

Are there any especially interesting keys to watch?

0

The following keys are well suited for planting a back door in one way or another. Always ensure the ACLs on these are ok. To keep track of changes or tries to change them, one can set up auditing on the keys as well. See 2.10.5 Auditing . • HKLM\SYSTEM\CCS\Services\LanmanServer\Parameters\NullSession{Shares|Pipes} This keys lists shares and named pipes that are accessible without logging in to the system, a so called NULL session connection (see 2.7.4 ). One scary aspect of this is that if you by coincident happen to create a share or named pipe which name matches any of the names in these lists, they are accessible from a NULL session connection. Note that the RestrictAnonymous key under Control/LSA mentioned in $$$: Q143474 does not prevent access to resources listed here. On a fresh NT 4.0, the defaults are: • Pipes: COMNAP, COMNODE, SQL\QUERY, SPOOLSS, LLSRPC, EPMAPPER, LOCATOR • Shares: COMCFG, DFS$. • HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Notification Packages Lists the DLLs

Related Questions

What is your question?

*Sadly, we had to bring back ads too. Hopefully more targeted.

Experts123