Quote:
you asked earlier about null sessions, the null session may be something that is vital to your infrastructure - but there's no reason to allow it out in the open, so at least firewall it. otherwise i would suggest disabling it. IT is what allows for the enumeration of shares, users, services, etc.
As soon as I get a firewall it is getting blocked. That is the first thing I am doing as soon as I hook the firewall up. Unfortunately, I'm really not sure if it is vital to my infrastructure or not. It is installed by default. I'm searching the web right now for more information on it. And I probably will disable it.