Windows 95/98 Network File Sharing Vulnerability
BID:188
Info
Windows 95/98 Network File Sharing Vulnerability
| Bugtraq ID: | 188 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | Jan 05 1999 12:00AM |
| Updated: | Jan 05 1999 12:00AM |
| Credit: | This was originally posted by Weld Pond ([email protected]) on Tue, 5 Jan 1999 00:24:59 -0500. The original post can be found at http://www.geek-girl.com/bugtraq/1999_1/0046.html |
| Vulnerable: |
Microsoft Windows 98 Microsoft Windows 95 |
| Not Vulnerable: | |
Discussion
Windows 95/98 Network File Sharing Vulnerability
A vulnerability exists in the way Microsoft Windows 95/98 accepts authentication for its shares. Windows 95/98 will accept the same hashes within a 15 minute period for authentication of a share. An attacker could modify the samba client to provide the hash intead of a password to authenticate to a Windows 95/98 share.
A vulnerability exists in the way Microsoft Windows 95/98 accepts authentication for its shares. Windows 95/98 will accept the same hashes within a 15 minute period for authentication of a share. An attacker could modify the samba client to provide the hash intead of a password to authenticate to a Windows 95/98 share.
Exploit / POC
Windows 95/98 Network File Sharing Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].