RE: Basic question

From: Craig, Tobin (OIG) (tobin.craig_at_va.gov)
Date: 03/10/05

  • Next message: Matt Ostiguy: "Re: Question on IIS servers and reverse lookup"
    Date: Thu, 10 Mar 2005 16:15:50 -0500
    To: "Roman L. Daszczyszak II" <romandas@gmail.com>, <focus-ms@securityfocus.com>
    
    

    There is a broad explanation of each in the textbook "Scene of the
    Cybercrime" by Debra Littlejohn Shinder. It only glosses over the
    surface of each, but might be useful if you are trying to present the
    concept at a high level.

    Tobin

    ___________________________
    Tobin Craig, MRSC, CISSP, SCERS, EnCE
    Program Director, Computer Crimes and Forensics
    Department of Veterans Affairs
    Office of Inspector General
    ___________________________

    -----Original Message-----
    From: Roman L. Daszczyszak II [mailto:romandas@gmail.com]
    Sent: Thursday, March 10, 2005 3:57 PM
    To: focus-ms@securityfocus.com
    Subject: Basic question

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Does anyone have a good reference on the differences between LanMan,
    NTLM, NTLMv2 and Kerberos? Also, is there any restriction on the length
    of a password used across a network/LAN for authentication? I'm aware
    in NT/2K/XP/2003 the max length of a password is 127 characters, but am
    curious if this is still true for network/domain authentication.

    Lastly, I have heard (and would like confirmation/denial) that
    authenticating to a domain-based machine from a machine outside the
    domain causes an otherwise normally encrypted password to be sent
    cleartext when authenticating with an IIS server. Can anyone point me
    to references about this?

    Thank you for any information y'all can provide.

    Roman
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.6 (GNU/Linux)
    Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

    iD8DBQFCMLSUszjStpsfjf8RAtNLAJsGmQv5p9B1bk7msxzK0zrDkpcSKgCgxEKl
    hoC2TjFp71dLF3Regw1c6qA=
    =vQB2
    -----END PGP SIGNATURE-----

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Matt Ostiguy: "Re: Question on IIS servers and reverse lookup"

    Relevant Pages

    • Basic question
      ... Does anyone have a good reference on the differences between LanMan, ... curious if this is still true for network/domain authentication. ... authenticating to a domain-based machine from a machine outside the ... Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org ...
      (Focus-Microsoft)
    • Re: ssl scp authentication
      ... You need GnuPG to verify this message ... > Is there a way to script the scp command to include the authentication? ...
      (comp.unix.shell)
    • Re: Pam modifications
      ... your using some other form of authentication. ... (I saved the originals to 'roll back' to the original ... thus the account can't be locked. ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org ...
      (Ubuntu)
    • Re: secure transfers and authentication
      ... certificates from our Certificate authority to do the authentication and ... then https to transfer the data. ... Comment: Using GnuPG with CentOS - http://enigmail.mozdev.org ...
      (Security-Basics)
    • Re: [opensuse] ODF files on SMB/CIFS share
      ... Manne Merak wrote: ... each request for a resource requires an authentication request ... (whether or not authentication is actually required). ... Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org ...
      (SuSE)