RE: LM and NTLM Hashes

From: Roger A. Grimes (roger_at_banneretcs.com)
Date: 09/09/05

  • Next message: Steven Kalcevich: "Re: I've passed the CISSP exam, few months back...Now what???"
    Date: Thu, 8 Sep 2005 18:17:21 -0400
    To: "Flavio Braga" <flaviobs@uol.com.br>, <security-basics@securityfocus.com>
    
    

    Telnet, Pop3, and FTP all send clear-text passwords by default. If
    you're using Outlook or OE with Exchange, you can enable SPA (Secure
    Protected Authentication..or something like that) in both the client and
    server. If it is another combination, then you can use IPSec, SSL, or
    something like that to encrypt communications.

    Roger

    ************************************************************************
    ***
    *Roger A. Grimes, InfoWorld, Security Columnist
    *CPA, CISSP, MCSE: Security (2000/2003/MVP), TICSA, CEH, CHFI
    *email: roger_grimes@infoworld.com or roger@banneretcs.com
    *Author of Honeypots for Windows (Apress)
    *http://www.apress.com/book/bookDisplay.html?bID=281
    ************************************************************************
    ****

    -----Original Message-----
    From: Flavio Braga [mailto:flaviobs@uol.com.br]
    Sent: Tuesday, September 06, 2005 12:56 PM
    To: security-basics@securityfocus.com
    Subject: LM and NTLM Hashes

    I saw that pop3 clients send passwords in text mode. Is there any way to
    protect passwords from email clients? Or the users have to access emails
    from webmails?


  • Next message: Steven Kalcevich: "Re: I've passed the CISSP exam, few months back...Now what???"

    Relevant Pages

    • Re: [Full-disclosure] Off topic rant to my friends
      ... I dunno if this is any worse than the many, ... went to a security conference users got insulted. ... SUSAN and BOB" were not good passwords. ... I do it to protect my company's investment. ...
      (Full-Disclosure)
    • key_read: missing keytype
      ... I have an OpenSSH server v3.8 on a linux machine. ... My objective is to use pubkey authentication only, and NO passwords. ... I have several linux clients that can connect to the sshd without problem, ...
      (comp.security.ssh)
    • Re: More SSH trolling
      ... > against the usage of secure passwords. ... SSH's encryption does protect effectively against ... "useless" since most attackers worldwide do not have the ability to ... standard security measures... ...
      (Fedora)
    • Re: building a server web FTP with apache
      ... SSH with chroot cages (plenty of Windows SCP/SFTP clients can support this). ... FTP(with all its poor security limitations, which make passwords vulnerable ... DAVExplorer used as a Java applet to make it entirely web form based. ...
      (comp.os.linux.security)
    • [NEWS] SAP R/3 Default Password Vulnerability
      ... As many ERP software packages SAP R/3 is capable of installing different ... Whereas the default passwords are normally changed in production clients, ... A typical SAP R/3 installation consists of at least 4 clients. ...
      (Securiteam)