Check: DNS4580
Windows DNS:
DNS4580
(in version v4 r1.19)
Title
Shares other than the default administrative shares are enabled on a name server. (Cat II impact)
Discussion
Non-administrative shares are unnecessary for name server operation and provide adversaries with an additional possible point of attack.
Check Content
From a command prompt, type net share and press enter. If any shares appear other than default administrative shares (e.g., C$, NETLOGON$), then this is a finding
Fix Text
The SA should disable all non-administrative shares.
Additional Identifiers
Rule ID: SV-3625r2_rule
Vulnerability ID: V-3625
Group Title: Shares are enabled on name server.
Expert Comments
Expert comments are only available to logged-in users.
CCIs
CCIs tied to check.
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Controls tied to check. These are derived from the CCIs shown above.
Number | Title |
---|---|
No controls are assigned to this check |