Re: Potential vulnerabilities of the Microsoft RVP-based Instant Messaging

From: Russ (Russ.Cooper@RC.ON.CA)
Date: 03/20/02


Date:         Wed, 20 Mar 2002 10:48:52 -0500
From: Russ <Russ.Cooper@RC.ON.CA>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

Further to Greg's comments about this Encode Security Labs analysis of
MS Instant Messaging, a couple of things seem not to be pointed out in
the analysis.

1. Exchange Server 2000 Instant Messaging supports the use of NTLM for
authentication, as opposed to the Digest Authentication described and
used in the analysis. The use of NTLM significantly alters the analysis,
since it addresses man-in-the-middle attacks, unilateral authentication,
and data origin authentication.

2. Confidentiality is still an issue when NTLM is used, but that's
simply because the protocol is a plaintext protocol.

3. Ad hoc communications with untrusted Internet-based IM clients can be
restricted, so if that's a concern, it can be addressed.

Cheers,
Russ - NTBugtraq Editor



Relevant Pages

  • RE: ADS Password Storage Protection
    ... In Windows it is LM or NT (sometimes called NTLM) hashes. ... NTLMv2 refers to the authenication protocol that exchanges the hash ... between the client and server authentication database. ...
    (Security-Basics)
  • Re: Integrated Windows Authentication Timeout?
    ... Is it possible that a different host name is being used for one of the subsequent requests that would break Kerberos auth? ... If you have "Negotiate" authentication set in the metabase, then this can still negotiate down to NTLM if for some reason the protocol thinks that Kerberos is unavailable. ... server. ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • RE: HttpWebRequest over Https Via Proxy Fails using NTLM
    ... The proxy authentication header returns Basic, NTLM, and Negotiate. ... A network trace shows that the https request handshake is as follows: ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: Event log shows NTLM not Kerberos
    ... it needs those SIDs, which is what authentication gives. ... Authentication Package: NTLM ... Authentication Package NTLM not Kerberos? ...
    (microsoft.public.security)
  • Re: Outlook 2000 issue with EXCH 2003
    ... It is related to DNS, the GC utilize DNS to find NTLM ... we have tested outlook 2k3 with NTLM only ... the LAN MAN authentication set to ...
    (microsoft.public.exchange.admin)

Quantcast