Re: brute-forcing NTLM HTTP Authentication

From: freehold@erols.com
Date: 09/29/01


Message-ID: <3BB633A4.16B1@erols.com>
Date: Sat, 29 Sep 2001 16:49:29 -0400
From: freehold@erols.com
To: Jason binger <cisspstudy@yahoo.com>
Subject: Re: brute-forcing NTLM HTTP Authentication

Lanman's challenge/response-based and it can cave when bruteforced.
There was a patch released some time ago because of a potential
Lophtcrack brute-force between IIs & clients w/ WEC (ME & anything with
Office2000). WEC didn't play nice with IE zone settings. Ditto a 2k
telnet client/ntlm problem (the client is 'optional' but enabled by
default I think). Ditto Netbios/ntlm. Windows sends the auths without
telling users, another example of 'transparency' I guess? ;)

My favorite ntlm-for-dummies: http://www.innovation.ch/java/ntlm.html

Missy

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • Re: how many clients per server w/ nessus?
    ... We accidentally just had 9 concurrent scans running from various clients. ... The server is a Netra X1 running Solaris 2.8. ... >> This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • SQL injection - get more values
    ... i'm trying to get some info from clients table and email field.... ... ') union select sumfrom clients-- ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • Re: SQL injection - get more values
    ... and go on submitting 'convert(int,(select email from clients where email not ... >- This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • Re: SQL injection - get more values
    ... (SELECT email FROM clients WHERE email NOT IN ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)
  • pen test help please asap
    ... I intend to get a trojan installed onto the clients network via ... I was hoping that someone out there in pen test land already had developed ... Machine A on client site makes a configurable encrypted OUTBOUND connection ... This list is provided by the SecurityFocus Security Intelligence Alert ...
    (Pen-Test)