Security Basics mailing list archives

Re: security-basics Digest 18 Jun 2003 22:09:15 -0000 Issue 618


From: Ansgar Wiechers <bugtraq () planetcobalt net>
Date: Thu, 19 Jun 2003 19:06:27 +0200

On 2003-06-19 Damon McMahon wrote:
The telnet built into Windows 2000 uses NTLMv2 authentication by
defalt.  While this is not 3DES or RC4, it is still not plain text.

Running windump on a Windows 2000 client and tcpdump on a MacOSX 10.1
client shows the login: and password: transmitted in clear text to a
Windows XP telnet server.

Can you specify any documentation stating NTLM is used?

The telnet service built into Windows NT can be configured to use either
NTLM, Login or both (first NTLM, then Login if NTLM fails). NTLM is the
default.

http://support.microsoft.com/?kbid=233069

Regards
Ansgar Wiechers

---------------------------------------------------------------------------
Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!
The Gartner Group just put Neoteris in the top of its Magic Quadrant,
while InStat has confirmed Neoteris as the leader in marketshare.
     
Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.
          
Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------


Current thread: