Re: LM or NTLMv1 or NTLMv2

From: Eric Chamberlain (eric_james_chamberlain_at_hotmail.com)
Date: 05/02/03


Date: Fri, 2 May 2003 10:19:36 -0700


You can try the ScoupLM tool at www.securityfriday.com. It will show what
the inbound SMB traffic is using.

"youpski" <youpski@remove_hotmail.com> wrote in message
news:01b401c30fe6$8acfe140$3401280a@phx.gbl...
> Hi, is there a way of auditing whether clients use
> LM/NTLMv1 or NTLMv2 to logon to my W2K AD domain
> controller? We want to eliminate LM but need to know
> first if it is still used. When you look at the security
> Event ID's 540, I only see Authentication Package: 'NTLM'
> or 'Kerberos' logged. Does this event log an LM
> authentication as "Authentication Package: LM" or is
> there no difference in the logging for LM/NTLMv1 or
> NTLMv2. Does anybody know how I can check which version
> of LM or NTLM down-level clients or applications like
> samba use? I don't have the abbility to locally check
> thousands of clients or applications so this needs to be
> checked from the Domain Controller.
>
> Please do not reply with 'you should not allow LM or
> NTLMv1 at all', 'just disable the use of LM in the
> security policy' or other well-intentioned advice. I
> understand the risk of LM just fine.. that is why we
> would like to eliminate it.
>
> thnx Y



Relevant Pages

  • Re: File/print sharing between 98/XP/2003 Mixed Domain
    ... the other on how to enable ntlmv2 on a W98 computer. ... In addition for the mean time in both Domain Security Policy and Domain Controller ... > several Windows 98SE clients that have shared printers. ...
    (microsoft.public.win2000.networking)
  • Re: File/print sharing between 98/XP/2003 Mixed Domain
    ... > In addition for the mean time in both Domain Security Policy and Domain Controller ... >> All clients are required to login to the domain, ... >> sharing the printer and the pc trying to connect to the printer. ...
    (microsoft.public.win2000.networking)
  • Re: LM or NTLMv1 or NTLMv2
    ... how to enable ntlm v2 for 9x and nt 4 and older clients, ... > thousands of clients or applications so this needs to be ... > security policy' or other well-intentioned advice. ...
    (microsoft.public.win2000.security)
  • Re: The Economics of Incompetence
    ... I use my clients as references, ... show applications that I developed, which gives a sense of what I ... it was suggested I let the user key up to 5 invoice numbers. ... a character is an uppercase A-Z -- I'd do that by checking the ascii ...
    (microsoft.public.dotnet.general)
  • Netlogon 5783
    ... For about there mounts I<m having small network problem, with clients, that ... The session setup to the Windows NT or Windows 2000 Domain Controller ... On DC1r there is Exchange 2000 server, witch is Exchange system manager is ... The failure code from authentication protocol Kerberos ...
    (microsoft.public.win2000.networking)