RE: Attacking EFS through cached domain logon credentials
From: John Howie (JHowie@securitytoolkit.com)
Date: 01/21/03
- Previous message: Dan Uscatu: "w2k server compromised"
- Maybe in reply to: Todd Sabin: "Attacking EFS through cached domain logon credentials"
- Next in thread: Todd Sabin: "Re: Attacking EFS through cached domain logon credentials"
- Reply: Todd Sabin: "Re: Attacking EFS through cached domain logon credentials"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 20 Jan 2003 22:32:12 -0800 From: "John Howie" <JHowie@securitytoolkit.com> To: "Todd Sabin" <tsabin@razor.bindview.com>, <bugtraq@securityfocus.com>, <focus-ms@securityfocus.com>
Todd (and lists),
You wrote:
>
> This is not completely correct, and I wanted to clarify how an attack
> against a domain-member's EFS encrypted files can work. The threat
> model is this:
>
It is important to distinguish between a weakness in EFS (there is none,
as described here) and the risk associated with using cached logon
credentials.
It is not just EFS which is at risk through 'cracking' an account like
you describe, there are so many other 'secrets' in a user's profile
including passwords to websites remembered by IE, POP3 email account
passwords in Outlook and Outlook Express, VPN passwords, etc.
Truly sensitive data should not be stored on a laptop, and when it must
use two-factor authentication such as a Smart Card (which does reduce
the risk associated with cached logon credentials) or a SecureID token.
If nothing else, some laptops these days come with passwords to
lock/unlock the hard drive.
Regards,
John Howie CISSP MCSE
President, Security Toolkit LLC
- Next message: Ed Sunder: "Stopping Admin Alert SPAM"
- Previous message: Dan Uscatu: "w2k server compromised"
- Maybe in reply to: Todd Sabin: "Attacking EFS through cached domain logon credentials"
- Next in thread: Todd Sabin: "Re: Attacking EFS through cached domain logon credentials"
- Reply: Todd Sabin: "Re: Attacking EFS through cached domain logon credentials"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|