Analysis of Windows 2000 Null Session Securiy
Qiang Wei · Journal of Information Engineering University · 2003
In this paper, the authors mainly discuss the security of Windows 2000 null session.Compared with other security problems, null session has not yet attracted more people's attention because it is a default system service.But recently, attacks arise because of the exploitation of null session(or IPCS|), and hackers always invade remote hosts through the exploitation together with other system holes.The threat it brings to users is the same as the IIS holes.The authors introduce the mechanism of the Windows 2000 null session, and analyse its security, and finally present the resolution to the vulnerability.