Solved

Disable NULL BASE queries on LDAP server

Posted on 2009-04-02
7
5,745 Views
Last Modified: 2013-12-04
Hello

A recent network scan has identified this potential vulnerability. I realise that it may not be an actual vulnerability (which would depend on access lists), but the fact is that this is an e-commerce server and we are required to get a "clean" network scan so this "problem" must be fixed.

The machine is standalone SBS 2003 SP2 running IIS 6 without SQL server or exchange. Basically it is just a webserver.

This problem did not exist on our last scan 3 months ago and there have been no configuration changes that I am aware of. Also, I have checked this
http://support.microsoft.com/kb/837964
In particular, the RestrictAnonymous registry setting is already set to 2 here
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA

I have also verified that the dsHeuristics attribute is not defined on the DN path as follows:
CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,Root domain in forest

Any help or advice would be much appreciated.

Thanks
LR
0
Comment
Question by:longrob604
  • 3
  • 3
7 Comments
 
LVL 6

Expert Comment

by:matt_beatt
ID: 24055868
I dont think you want to be doing that im afraid!  I take it this servers is running as a DC and web server - correct?

My understanding of LDAP in an AD environment is that the RootDSE query is anonymous and is a requirement for Clients to be able to obtain certain vital information about the LDAP directory.  RootDSE query is where Base="" ie: Null Base Search.  If you dont have this, AD wont work and therefore neither will anything you have reliant on AD!
0
 

Author Comment

by:longrob604
ID: 24056046
Hi Matt

Thanks for your message.  There are no clients, since this is a standalone webserver. We never had this problem with null base queries before, and as mentioned, accoriding to the KB we have it disabled already ! Yet the network scan shows otherwise. We had a seperate network scan from a another company just to make sure, and that also gave the same result. Also, this is a *requirement* for anyserver that needs to be PCI compliant and that would basically be any e-commerce servier, so this must be a very common problem, but the only solutions I can find to it do not apply to our situation.

Thanks again
LR
0
 
LVL 6

Expert Comment

by:matt_beatt
ID: 24057318
I think the key thing to note that it doesnt completely Disable Null base queries it only minimizes the information that it provides.   Run LDP from a laptop or other none domain machine and connect to your server and you'll see that you still get domain information.  Perhaps if you look thru that and find out specifically what the network scan is complaining about.  Whether its a piece of specific information or just the fact the a null connect is givinig out information at all
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:longrob604
ID: 24057406
Hi Matt

Thanks again. This is specifically what the network scan is complaining about. They don't give any more information

Remedial action: Disable NULL BASE queries on your LDAP server. This issue is only
applicable on internet-facing hosts.
******************************
LDAP Null Base
Improperly configured LDAP servers will allow the directory BASE to
be set to NULL. This allows information to be culled without any prior
knowledge of the directory structure. Coupled with a NULL BIND, an
anonymous user can query your LDAP server using a tool such as
'LdapMiner'. If this is an internal scan, and the system is a Windows
Active Directory server, this is normal behavior and there is nothing to
do.
************************
and
***********************
LDAP Bind Overflow
Improperly configured LDAP servers will allow any user to connect to
the server and query for information.
Remedial action: Disable NULL BIND on your LDAP server
***********************

BTW, It is not an internal scan - they have done this scan from the internet.

Thanks in adavce
LR
0
 
LVL 6

Accepted Solution

by:
matt_beatt earned 500 total points
ID: 24057428
Why do you need to have access to this server from the internet on port 389/tcp?  If you lock your firewall down so that access via the internet was not available then you wouldnt get this error
0
 

Author Comment

by:longrob604
ID: 24057636
Hi again Matt. That may be a great solution. I will investigate !
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

A quick step-by-step overview of installing and configuring Carbonite Server Backup.
Container Orchestration platforms empower organizations to scale their apps at an exceptional rate. This is the reason numerous innovation-driven companies are moving apps to an appropriated datacenter wide platform that empowers them to scale at a …
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now