I do!
They did a pen test on our customers network recently and found a whole bunch of stuff I have to now go fix, not necessairly because they are huge loopholes, but simply because their security tools deem them as risks. This one I am stuck on completely:
Group Enumeration through SMB Service-
Unfortunately I don't have a scooby doo (cockney ryhming slang for clue) what this in essence means, or how if effects their network in the slightest. Excuse my lack of security experience but the only relevant technet link I can find involves the actual change itself:
http://technet2.microsoft.com/windowsserver/en/library/bfba3c82-b2c2-49e2-a5eb-92a3cd620afc1033.mspx?mfr=true
The note at the bottom causes a huge problem for me, in that their AD environment does run in mixed mode and not native....so we have a problem there.
Can anyone shed any light on this at all? If so it would be a great help.
Cheers,