ABSTRACT

Secure access control lists (ACLs), Restrict Anonymous, host-based firewalls

Description:

The NULL session is used on Windows computers via the Inter-Communication Process (IPC$) to allow the viewing of shared resources. This connection is made without a username or password. An attacker will use the NULL session to his or her advantage to enumerate user information from the target. Many enumeration labs are more successful when establishing a NULL session.