About opening your guest account!!

I have been reading some of the posts here and alot of ppl are telling you to open your guest accounts. It sould be noted that while on a internal network that may be fine...but if you open the guest account on a pc that has direct access to t...




Topic Options
#54460 - 04/10/00 09:09 AM About opening your guest account!!
Neirret Offline
stranger

Registered: 04/09/00
Posts: 7
I have been reading some of the posts here and alot of ppl are telling you to open your guest accounts.

It sould be noted that while on a internal network that may be fine...but if you open the guest account on a pc that has direct access to the internet be warned anyone now has access to snoop you shares.

My 2 cents worth

Top
Advertisement
#54461 - 04/10/00 09:45 PM Re: About opening your guest account!!
s p i n a l Offline
stranger

Registered: 09/05/99
Posts: 9
I totally agree. I think it is better security and practice to create user accounts for those boxes you wish to have access to your shares in NT or 2000.

Guest access is a cheap hack that can come back and bite you in the butt.

Top
#54462 - 04/11/00 05:40 AM Re: About opening your guest account!!
Andersony Offline
newbie

Registered: 01/07/00
Posts: 46
Ditto...

and don't leave your administrator account without a password !

[This message has been edited by Andersony (edited 11 April 2000).]

Top
#54463 - 04/12/00 10:33 AM Re: About opening your guest account!!
simonroockley Offline
newbie

Registered: 03/06/00
Posts: 44
As long as you password your guest account with a different one from the default. Then you have as much protection as you do with any other login. The main point is to disable file and printer sharing for any direct connection to the internet.
Having the guest account enabled is the only way to allow other machines in a workgroup style network have acces to shares on any NT based machine.

Top
#54464 - 04/12/00 11:20 AM Re: About opening your guest account!!
YuppieScum Offline
addict

Registered: 07/16/99
Posts: 617
Sorry Simon, but bollocks.
Quote:
As long as you password your guest account with a different one from the default. Then you have as much protection as you do with any other login.

No you don't, you have half as much protection, as attackers already know the username - they just have to crack the pwd.

And further bollocks...
Quote:
Having the guest account enabled is the only way to allow other machines in a workgroup style network have acces to shares on any NT based machine.

Wrong. For small networks, create user accounts under W2K with the same username and password as the Win9x logins you wish to grant access, then permission the W2K shares accordingly.
For larger networks, make a W2K machine a domain controller, and have all the W9x boxes authenticate via that...



[This message has been edited by YuppieScum (edited 12 April 2000).]

Top
#54465 - 04/12/00 05:59 PM Re: About opening your guest account!!
SHS Offline
veteran

Registered: 07/16/99
Posts: 1245
There nothing wrong with enable guest accounts, If you runing small Local Lan at Home or Small Buiss with less then 8 PC.
But his it will depend on how setup you Internet Gateway.

The Internet Gateway Server.
1: By defult this should be Uncheck "Files and Sharing for Microsoft Networks" on one the following Adapter: Modem Adapter, PCI Ethernet Adapter, USB Ethernet Adapter what ever card you are useing as your Internet Connection to that ISP.

2: Services that you should turn off
Messenger, Remote Registry Service unless you plan on run a domain controller for that you will need Windows2000 Server.

Top
#54466 - 04/12/00 06:09 PM Re: About opening your guest account!!
simonroockley Offline
newbie

Registered: 03/06/00
Posts: 44
Reference knowing the guest account name is guest lowers security, you mean like knowing the administrator logon is administrator or root on unix? (bollocks?) If you are going to call a statement bollocks think about the whole picture and not part of it.

Again the best defence for securing any account is a decent password.

Also the same username and password option does not always work. I've still seen instances where in NT4 it still asks for the IPC password and Win2K where it presents you with the access permissions error.

Top
#54467 - 04/13/00 12:17 AM Re: About opening your guest account!!
DosFreak Offline
Carpal Tunnel

Registered: 02/04/00
Posts: 3868
Loc: Georgia
Wow, So you leave your Administrator and Guest accounts as "Administrator" and "Guest"!!!!??? Hmmm. What company do you work at and where? I would like to show you something..... wink

Top
#54468 - 04/13/00 07:08 AM Re: About opening your guest account!!
SHS Offline
veteran

Registered: 07/16/99
Posts: 1245
who are talk to DosFreak ?.

Top
#54469 - 04/18/00 06:30 AM Re: About opening your guest account!!
Feral Offline
newbie

Registered: 07/18/99
Posts: 45
I work for a large IT company... And to prevent unwanted access... we change the name of administrator accounts on "ALL" Nt based machines. And for even "more" security. We disable all guest acounts.. Now for internet access... THats a whole nother story..

Just my 50 cents and a penny.

------------------
When the world comes to a halt, Hold The F*** ON!!!

Top
#54470 - 04/18/00 10:54 AM Re: About opening your guest account!!
Volitaire Offline
stranger

Registered: 01/12/00
Posts: 22
Yeah.. your supposed to change the Admin.. but i found a better way... take away all the privs in Admin name.. make super pass like blahbkajdksfjlj29830423.. so they spend like 4 years cracking it to get no access =)..



------------------
Volitaire
A+, MCSE, MCP+I, ACT

Top
#54471 - 04/19/00 09:10 PM Re: About opening your guest account!!
SocialChaos Offline
stranger

Registered: 04/19/00
Posts: 3
nah, i still believe in runnin my good ol' BlackIce Defender on the lan and sharin whatever i want without worrying....block them ports baby!

Top
#54472 - 04/25/00 07:15 AM Re: About opening your guest account!!
Intlharvester Offline
journeyman

Registered: 04/25/00
Posts: 90
First, if you have Cable or DSL, get two ethernet cards. Don't do local file sharing on the same interface as the Internet connection.

Second, disable "Client for MS Networks" and "File/Print Sharing" on the Internet connected interface (Ethernet or dial-up).

On the second, "internal" interface you can run filesharing. You can use a private IP address like 10.x.x.x, but I just use NetBEUI because it's faster and less of a hassle and won't 'leak' onto the Internet under any circumstances. Don't enable IP forwarding, either.

If you are keeping your file sharing to a local, disconnected interface, you can enable the guest account without worry.

Top
#54473 - 05/14/00 03:14 AM Re: About opening your guest account!!
4T2 Offline
journeyman

Registered: 05/14/00
Posts: 6
OK guys, first off if you have any netbios sharing enabled on the interface that is public a simple nbtstat will get the user name that is loggin in. There goes your extra security by renaming the user.

However it is still a good idea to rename them. And DON'T enable your guest account, your only asking for trouble. Create user accounts that the other machines have. NO GUEST!!!

Top
#54474 - 05/15/00 12:25 AM Re: About opening your guest account!!
mjolnirGS Offline
newbie

Registered: 05/12/00
Posts: 5
I just thought I'd like to throw in my 2 cents...

My Opinion is that 75 to 80% of hackers out there are not very good or creative, they just download port scanners, password crackers and all kinds of other goodies from the internet. Then they scan Massive blocks of IP addresses looking for easy targets.

What is an Easy target? NT or Win95 machines that are displaying all of their NetBIOS goodies out there for all to see. They try the obvious stuff first, Administrator accounts, Guest account, FTP ports, etc. If the Easy stuff doesn't work they move on to a better target.

In my opinion, to protect yourself from these guys, do the following. Disable file and print sharing, and remove all bindings to the TCP/IP protocol (exept the one binding the protocol to the adapter)on the interface exposed to the internet for Win95.

For WinNT, open the network applet, go to TCP/IP properties, select the bindings tab, choose "all adapters". For the exposed adapter, disable the NetBIOS interface, Server, and Workstation services. (this does not affect your internet access)

Then rename your administrator account, give it an impossible password and disable the guest account.

Finally, get a good firewall to block all 65,000 + TCP ports on your machine. I recomend ZoneAlarm from Zone labs, It is easy to figure out, easy to use, blocks traffic Both ways (if you want it to) and most of all, It's free! Get it at www.zonelabs.com. also check out http://grc.com (very cool internet site, what you find may shock you)

For the other 20 to 25% of the hackers out there, you can bet that for every thing you think is impossible for them to do, Some clever genius has figured out a way to do it. All you can really hope for if one of these guys sets his sights on you is that he is nice to your system while he visits smile


------------------
MjolnirGS@hotmail.com

[This message has been edited by mjolnirGS (edited 15 May 2000).]

Top


Forums
Windows Support Forums
Everything New Technology
Legacy OS
Hardware
Software
Games
Networking
Customization & Tweaking
Security

Linux Support Forums
Everything Linux
Linux Hardware
Linux Software
Linux Games
Linux Networking
Linux Customization & Tweaking
Linux Security

Apple Support Forums
Everything Apple
Recent Topics
Need an database for Dictionary
by shaanspecial
1 second ago
Christmas Gift: Some Discount Packs about Multimed
by Autumm007
27 minutes 33 seconds ago
Router keeps disconnecting internet
by rfboyd
12/06/09 04:18 PM
Program Running When Starting Computer
by cbk
12/05/09 11:05 AM
System Crashing Error 1000008e, 1000000a, 0000004e
by PapaPrem
11/30/09 06:01 PM
Who's Online
3 Registered (Autumm007, rkmoorthy, shaanspecial), 202 Guests and 33 Spiders online.
Key: Admin, Global Mod, Mod
Forum Stats
91284 Members
24 Forums
58529 Topics
189033 Posts

Max Online: 1079 @ 03/12/08 01:36 PM

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22