Unrestricted SMB Access


Summary

Server Message Block (SMB) files shares are world accessable. SARA could access an SMB share. SARA could do a directory listing of the indicated share. No attempt was made to read or write to the contents of the directories.

Impact

The Problem

This vulnerability allows hackers to access files that have been "shared" to the world without the need of a password or special account.

Fix

Confirm that there are no open shares that allow universal access. This is true for Microsoft Windows and Unix operating SAMBA.