Security Basics mailing list archives
Re: sshd for windows
From: "Chris Berry" <compjma () hotmail com>
Date: Thu, 19 Jun 2003 12:04:54 -0700
From: Ansgar Wiechers <bugtraq () planetcobalt net> On 2003-06-18 Richard Parry wrote: >> theres a builtin telnet server included with win2k (server and >> workstation). > > Oh yeah, thats the perfect way of breaking into a machine ! Telnet is > plain text, so is very easy to sniff anything that goes on ! I hope > you are being sarcastic ! You do know, that by default Windows is using NTLM authentication for telnet, don't you? Of course that's not comparable to ssh, but it sure is a lot better than plaintext authentication.
Thats totally true, but worthless. Authentication isn't the problem, it's the transmission that's in the clear, so now you're sending your loging name and password in cleartext. Sure, they're stored in NTLMv2 format at the other end, but what does that matter if they just put a sniffer on the wire?
Chris Berry compjma () hotmail com Systems Administrator JM Associates "Within every man beats a heart of darkness." --The Shadow _________________________________________________________________The new MSN 8: advanced junk mail protection and 2 months FREE* http://join.msn.com/?page=features/junkmail
--------------------------------------------------------------------------- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, while InStat has confirmed Neoteris as the leader in marketshare.Find out why, and see how you can get plug-n-play secure remote access in
about an hour, with no client, server changes, or ongoing maintenance.Visit us at: http://www.neoteris.com/promos/sf-6-9.htm
----------------------------------------------------------------------------
Current thread:
- Re: sshd for windows, (continued)
- Re: sshd for windows Pascal Junod (Jun 18)
- Re: sshd for windows Adam Newhard (Jun 19)
- Re: sshd for windows Pascal Junod (Jun 18)
- RE: sshd for windows DeGennaro, Gregory (Jun 18)
- RE: sshd for windows Depp, Dennis M. (Jun 18)
- Re: sshd for windows Bryan S. Sampsel (Jun 18)
- RE: sshd for windows Chris Berry (Jun 19)
- RE: sshd for windows DeGennaro, Gregory (Jun 19)
- RE: sshd for windows DeGennaro, Gregory (Jun 19)
- RE: sshd for windows wjnorth (Jun 20)
- RE: sshd for windows DeGennaro, Gregory (Jun 20)
- Re: sshd for windows Chris Berry (Jun 20)
- Re: sshd for windows Ansgar Wiechers (Jun 23)
- Re: sshd for windows ktabic (Jun 23)
- RE: sshd for windows Chris Berry (Jun 20)
- RE: sshd for windows Chris Berry (Jun 21)
- RE: sshd for windows DeGennaro, Gregory (Jun 21)
- RE: sshd for windows Chris Berry (Jun 21)
- RE: sshd for windows Depp, Dennis M. (Jun 21)
- RE: sshd for windows Depp, Dennis M. (Jun 21)
- Re: sshd for windows Chris Berry (Jun 24)