| VID |
28003 |
| Severity |
20 |
| Port |
137,138,139 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
The domain (or host) SID(Security Identifier) can be obtained by the call to LsaQueryInformationPolicy() or LookupAccountName(). The domain/host SID can then be used to get the list of users of the domain or the list of local users. |
| Recommendation |
Filter incoming traffic to the ports 137 to 139 |
| Related URL |
CVE-2000-1200 (CVE) |
| Related URL |
959 (SecurityFocus) |
| Related URL |
4015 (ISS) |
|