Yup. Well, you really should disable annonymous access and disable the default shares if you don't really need them. Or just blocking it at your firewall.

Check out
http://rusecure.rutgers.edu/add_sec_meas/nullssn.php