18.4.6 Ensure 'MSS: Allow the computer to ignore NetBIOS name release requests except from WINS servers' is set to 'Enabled'

Information

NetBIOS over TCP/IP is a network protocol that among other things provides a way to easily resolve NetBIOS names that are registered on Windows-based systems to the IP addresses that are configured on those systems. This setting determines whether the computer releases its NetBIOS name when it receives a name-release request. The NetBT protocol is designed not to use authentication, and is therefore vulnerable to spoofing.

Solution

Make sure 'MSS: (NoNameReleaseOnDemand) is Enabled'

See Also

https://workbench.cisecurity.org/files/1941

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-21, CSCv6|9

Plugin: Windows

Control ID: fa772bd9d7e692df189f1c16294a9bf0beda95fb8515d5af524d824be790d784