Re: MSFT Bans insecure hashes - was"Passwords with Lan Manager (LM) under Windows"

From: Daniel Miessler (daniel_at_dmiessler.com)
Date: 10/30/05

  • Next message: Daniel Miessler: "Re: Port Scanner Reports"
    Date: Sun, 30 Oct 2005 05:17:54 -0500
    To: Thor (Hammer of God) <thor@hammerofgod.com>
    
    
    

    On Sep 24, 2005, at 4:11 PM, Thor (Hammer of God) wrote:

    > Rather than getting into how the basic client-server authentication
    > netlogon protocols are vastly different than IPSec channels, please
    > just answer one of the following questions. I'll try to make them
    > very simple.
    >
    > Scenario: You've got an XP Pro laptop on the Windows network
    > logged on with local credentials. A network resource on a Win2k
    > server somewhere is accessed, requiring new credentials be entered
    > to access the resource. Please tell us exactly how you force the
    > client and server to use "IPSec based auth" to authenticate the
    > request as opposed to LM, NTLM, or NTLMv2.

    Here, let me try:

    The issue here is simple: we're trying to authenticate to a Windows
    system, and IPSEC "authentication" is used to authenticate IPSEC
    peers, not Windows users. An analogy would be a situation in which
    authentication is needed for both a secret road to get to work, and
    then also to enter the building at work. The road authentication
    doesn't necessarily work for the building. ;)

    -- 
    Daniel R. Miessler
    M: daniel@dmiessler.com
    W: http://dmiessler.com
    G: 0x316BC712
    
    



  • Next message: Daniel Miessler: "Re: Port Scanner Reports"

    Relevant Pages

    • Re: Disable ALL Lan Manager Authentication
      ... You can manage lan manager authentication level to allow only ... careful with Exchange and VPN servers. ... 98 or non domain computer to access the ipsec required server. ... > I'm in a pure Windows 2003 domain environment with Windows XP clients. ...
      (microsoft.public.windows.server.security)
    • Re: Passwords with Lan Manager (LM) under Windows
      ... "advisable to make IPsec-based authentication a part of the authentication ... For authentication, IPSec allows you to use the Kerberos V5 protocol, ... Passwords with Lan Manager under Windows ...
      (Pen-Test)
    • Re: Change in ASP.Net authentication between Win2000 and Win2003
      ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
      (microsoft.public.windows.server.security)
    • Re: Change in ASP.Net authentication between Win2000 and Win2003
      ... > is turning on/off Kerberos is occuring. ... It control how IE deals with "Authentication: ... when you put IIS6 in a domain and have "Integrated Windows Authentication" ...
      (microsoft.public.inetserver.iis.security)
    • Re: MSFT Bans insecure hashes - was"Passwords with Lan Manager (LM) under Windows"
      ... After I pointed out that "IPsec based auth" is not a basic netlogon ... authentication protocol like Kerberos, LM, NTLM and NTLMv2, you said I was ... based auth" to authenticate the request as opposed to LM, NTLM, or NTLMv2. ... Up to 75% of cyber attacks are launched on shopping carts, forms, ...
      (Pen-Test)