RE: NT4, IPC$, and password hashes

From: Nathan (nathan.grandbois@cerdant.com)
Date: 07/29/02


From: "Nathan" <nathan.grandbois@cerdant.com>
To: "'RUSSELL T. LEWIS'" <RUSSELL_T._LEWIS@spectralresponse.com>, <security-basics@securityfocus.com>
Date: Mon, 29 Jul 2002 09:13:19 -0400

Check to see if the default share is open. Close it and c$ will go away.

Nathan Grandbois
www.cerdant.com

-----Original Message-----
From: RUSSELL T. LEWIS [mailto:RUSSELL_T._LEWIS@spectralresponse.com]
Sent: Thursday, July 25, 2002 3:17 PM
To: security-basics@securityfocus.com
Subject: NT4, IPC$, and password hashes

I've got an NT 4 SP6a Workstation that I'm hardening and I've patched it all
the
way with HFNETCHK, and done ton of registry hacks, turned off services, etc.
However, if I type \\COMPUTERNAME on my network I can get a IPC$ and
LoftCrack3
can extract the password hash, which I've already cracked the lanman hash.
The
crack DID take forever (17days 5hrs 27min) on a p4 2.53GHz over clocked to
2.75
GHz, but I don't like the fact that the hash can be obtained.

How do I prevent LC3, or anyone from getting the password hash?
I did a few registry entries that were supposed to restrict remote registry,
but
it seems that didn't work, or isn't enough.
Thanks for any help!
-Russell



Relevant Pages

  • RE: NT4, IPC$, and password hashes
    ... It is my understanding that NTLM is not GRAS, ... NT4, IPC$, and password hashes ... way with HFNETCHK, and done ton of registry hacks, turned off services, etc. ... or anyone from getting the password hash? ...
    (Security-Basics)
  • RE: NT4, IPC$, and password hashes
    ... // How do I prevent LC3, or anyone from getting the password hash? ... // I did a few registry entries that were supposed to restrict ... did you set 'enumerate shares' to restrict anon? ... Did you also try to get the C$, ADMIN$, IPC$, LPT$ through 'net use'? ...
    (Security-Basics)
  • NT4, IPC$, and password hashes
    ... way with HFNETCHK, and done ton of registry hacks, turned off services, etc. ... or anyone from getting the password hash? ...
    (Security-Basics)
  • Re: $IPC share keeps disappearing
    ... >command every hour or so.. ... did you try looking at the registry? ... there might be an entry like net share ipc$ /delete /yes ...
    (microsoft.public.win2000.networking)