Re: NT user list publically available?

From: Thor Kottelin (thor@anta.net)
Date: 12/22/02


From: Thor Kottelin <thor@anta.net>
Date: Mon, 23 Dec 2002 00:22:52 +0200


Joey Ramone wrote:

> It seems that either a) non-user
> names aren't logged or more likely b) someone has found a way to get a
> list of usernames on the server. Is this a known hole that I haven't
> patched yet?

Yes. Have you been asleep for the last three years? :-)

<URL:http://www.windows2000faq.com/Articles/Index.cfm?ArticleID=14771>

Thor

-- 
http://thorweb.anta.net/		OH2GDF
                    PGP public key available


Relevant Pages

  • OT: muddleftpd config while running as a normal user
    ... I want to run muddleftpd as a normal user, ... one group is to catch invalid usernames ... # tell the server these usernames are disabled ... # This configures the normal users. ...
    (Ubuntu)
  • RE: MS Exchange Server 5.5/ NT User Name Harvesting ?
    ... With the Watchgaurd you can block specific sites, ... MS Exchange Server 5.5/ NT User Name Harvesting? ... The usernames are not guessable, the only common thread that all the ...
    (Focus-Microsoft)
  • RE: [PHP] Re: Securing user table with sha function
    ... needs a client could possibly want in the way of features by modulating each ... So i'm just mainly worried about my host server going down for whatever ... I write a book now about PHP and I want to help people ... if you crypt your usernames, ...
    (php.general)
  • RE: MS Exchange Server 5.5/ NT User Name Harvesting ?
    ... > attackers are trying to use your exchange server as ... >>server as a spam relay. ... >>like to know how to stop them from harvesting our ... >>The usernames are not guessable, ...
    (Focus-Microsoft)
  • Re: MS Exchange Server 5.5/ NT User Name Harvesting ?
    ... attackers are trying to use your exchange server as a spam relay? ... Our mail server is MS Exchange 5.5, ... >like to know how to stop them from harvesting our Usernames. ...
    (Focus-Microsoft)