Sign in with
Sign up | Sign in
Your question

"Hidden" admin shares

Last response: in Windows XP
Share
August 14, 2005 12:52:19 PM

Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

What are the "hidden" admin shares in XP Home and how are they a security
risk?


--

Johnson@naol.com

More about : hidden admin shares

Anonymous
a b 8 Security
August 14, 2005 1:19:57 PM

Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

From: "Jeff" <jeff@naol.com>

| What are the "hidden" admin shares in XP Home and how are they a security
| risk?
|
| --
|
| Johnson@naol.com
|

They are such shares as C$, D$, etc.

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters
Double click on AutoShareServer and set it to 0 to disable it for a server.
Double click on AutoShareWks and set it to 0 to disable it for a
workstation.
If the entries are not present, Add Value of type REG_DWORD. The Range is 0
(disable) or 1 (enable - the default).


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
Anonymous
a b 8 Security
August 14, 2005 4:57:46 PM

Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

From http://www.chicagotech.net/winxphome.htm#Can%20I%20disa...

My XP Home Edition does not automatically create any special shared ($) folders.
A: Because of security implications, Microsoft Windows XP Home Edition does
not automatically create the drive letter$, or Admin$ special shared folders.

Take a risk... try googling it on your own

> What are the "hidden" admin shares in XP Home and how are they a
> security risk?
>
Anonymous
a b 8 Security
August 14, 2005 7:09:39 PM

Archived from groups: microsoft.public.windowsxp.security_admin (More info?)

Jeff schrieb:

> What are the "hidden" admin shares in XP Home and how are they a security
> risk?

They can only be a security risk if you have administrative accounts with a
simple password set (that can be guessed by an attacker). If your
administrative account do not have a password set they can not be used to
access these resources from a remote machine.

Jan
!