diff options
author | Trevor Gamblin <trevor.gamblin@windriver.com> | 2019-12-23 19:55:43 -0500 |
---|---|---|
committer | Khem Raj <raj.khem@gmail.com> | 2019-12-25 08:55:26 -0800 |
commit | f29dfed64a56c9d952d18139d74adc1574ff79f4 (patch) | |
tree | 5cef8f05fae5f265f4b0af35e94fdd217103bf64 /meta-multimedia/recipes-multimedia | |
parent | 04b8b3916357537372a6e4aa016eda92b6d3d125 (diff) | |
download | meta-openembedded-f29dfed64a56c9d952d18139d74adc1574ff79f4.tar.gz |
samba: disable guest access and anonymous queries
Guest accounts for Samba are a known potential vulnerability
(see https://www.tenable.com/plugins/nessus/26919) where info
about the host can be obtained without proper access. The option
"map to guest = bad user" allows login attempts with usernames
that don't exist to map to the guest account, while the
"restrict anonymous" value (implicitly set to 0 before this patch)
would allow any queries to obtain user and group list information.
Raise the default security level by setting "restrict anonymous"
to "1" and "map to guest" to "never" to avoid providing user/group
info to unauthenticated users and reject login attempts with an
invalid password, respectively.
Signed-off-by: Trevor Gamblin <trevor.gamblin@windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
Diffstat (limited to 'meta-multimedia/recipes-multimedia')
0 files changed, 0 insertions, 0 deletions