Vulnerability Development mailing list archives

Re: NT 4.0 (Workstation) Logon Authentication Vulnerability


From: mrousseau () SECURED ORG (Maxime Rousseau)
Date: Wed, 15 Mar 2000 03:45:18 -0500


This is a configuration setting named "Number of logon credentials to cache"
that you can set to '0' or more depending on your policy. But if you see it
as a problem, by all means, set it to zero.

M.

-----Original Message-----
From: VULN-DEV List [mailto:VULN-DEV () SECURITYFOCUS COM]On Behalf Of
jhw1970 () HOTMAIL COM
Sent: Tuesday, March 14, 2000 8:19 AM
To: VULN-DEV () SECURITYFOCUS COM
Subject: NT 4.0 (Workstation) Logon Authentication Vulnerability


Scenario:  User logon to WinNT domain.

Problem:  I believe WinNT may cache user passwords.  This
allows a user to disconnect a terminal from the network and
login to the workstation locally without being
authenticated by the PDC or BDC.

Vulnerability:  A malicious user may disconnect a machine
from the network and add/remove software without being
audited by the PDC/BDC.  Also, a user who has been deleted
from the domain users list may still have access to a
machine which he/she had used in the past.



Current thread: