Vulnerability Development mailing list archives

Re: is this something?


From: Mike Sues <msues () cinnabar ca>
Date: Thu, 18 Jan 2001 07:33:22 -0500

I confirmed this on Win2K Server with NTLM=0 and all other
parms the default; using \\guest as the user name gave access
only when the Guest account was enabled (null password). I then assigned
a password to the Guest account and tried again; I needed to know the
correct password to gain access. The \\ appears to bypass the telnet
restriction on the Guest account but not any password assigned to Guest.

Mike Sues
Senior Network Security Analyst
Cinnabar Networks Inc

----- Original Message -----
From: "Phil Cox" <Phil.Cox () SystemExperts com>
To: <VULN-DEV () SECURITYFOCUS COM>
Sent: Wednesday, January 17, 2001 11:54 AM
Subject: Re: is this something?


I do not experience this. It says the account is disabled when trying to
login.

Phil

Telnet Server Build 5.00.99201.1
login: guest
Login through Guest account not allowed
login: \\guest
password:

*===============================================================
Welcome to Microsoft Telnet Server.
*===============================================================
C:\>


UNC dealy? misconfig? lack of config? lack of coffee?
Thank you for your time.



Current thread: