Re[2]: [Full-Disclosure] Automatically passing NTLM authentication credentials on Windows XP

From: Hidenobu Seki (urity_friday_at_hotmail.com)
Date: 09/29/04

  • Next message: Luigi Auriemma: "[Full-Disclosure] Code execution in Icecast 2.0.1"
    To: 3APA3A@SECURITY.NNOV.RU
    Date: Wed, 29 Sep 2004 18:10:42 +0900
    
    

    >From: 3APA3A <3APA3A@SECURITY.NNOV.RU>
    >
    >I don't think problem reported by you is different issue, it's just
    >another exploit scenario for the same problem. I know few more tricks to
    >redirect user to UNC share.

    I see your meaning. So, I agree.

    I hope Microsoft fundamentally address the issue in the future.
    In the meantime, I expect you (Microsoft) to do something for their problems
    piece by piece.
    Don't leave "img src=file://..." as it is for 7 years.
    I think many people use Windows by default but get WindowsUpdate. They
    aren't aware that they use weak LM authentication.

    Kind regards,
    Urity

    _________________________________________________________________
    MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*.
    http://join.msn.com/?page=features/virus

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Luigi Auriemma: "[Full-Disclosure] Code execution in Icecast 2.0.1"

    Relevant Pages

    • Re: Pre-Scanning for Marketing
      ... consider the scenario that you were going through the neighborhood seeing if windows are unlocked. ... If that scenario doesn't strike you as so over-security-conscious that it's idiotic, then you should know it is indeed a Sponge Bob episode. ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)
    • Re: Windows XP startup best practice?
      ... Is there a way to make Windows XP automatically log the user off when he ... I am looking for guidance beyond the obvious (some ... trainer to signal that the training scenario is ready to run, ...
      (microsoft.public.windowsxp.customize)
    • Re: Windows XP startup best practice?
      ... Startup in this discussion group). ... trainer to signal that the training scenario is ready to run, ... I also need to be able to shutdown the ... "Is there a way to make Windows XP behave this way?" ...
      (microsoft.public.windowsxp.customize)
    • Re: But There Aint No Global Warming.
      ... > global warming before buying into this end of the world scenario ... ears at every presentation of evidence and say, ... softness of the rubber balls they're using, ... assert that the windows are all robustly intact. ...
      (sci.energy)
    • Re: But There Aint No Global Warming.
      ... > global warming before buying into this end of the world scenario ... ears at every presentation of evidence and say, ... softness of the rubber balls they're using, ... assert that the windows are all robustly intact. ...
      (sci.energy.hydrogen)

  • Quantcast