NT RAS Dial-up Networking "Save Password" Vulnerability
BID:232
Info
NT RAS Dial-up Networking "Save Password" Vulnerability
| Bugtraq ID: | 232 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Mar 19 1998 12:00AM |
| Updated: | Mar 19 1998 12:00AM |
| Credit: | This vulnerability was posted to NTBugtraq by Lisa O'Connor, Martin Dolphin, Joe Greene, and Eric Schultze. |
| Vulnerable: |
Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Exploit / POC
NT RAS Dial-up Networking "Save Password" Vulnerability
Execute LSA Secrets (or similar) code against the HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\RasDialParams!SID#0 registry key. Refer to NT LSA Secrets Vulnerability, July 16,1997
Execute LSA Secrets (or similar) code against the HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets\RasDialParams!SID#0 registry key. Refer to NT LSA Secrets Vulnerability, July 16,1997
Solution / Fix
NT RAS Dial-up Networking "Save Password" Vulnerability
Solution:
Microsoft has released a hotfix for NT 4.0 SP3 machines that prevents enumeration of the LSA secrets. This hotfix can be found at: ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/hotfixes-postSP3/lsa2-fix/
This hotfix has been included in Service Pack 4.
However, the LSA-2 patch does not prevent the username, phone number, and password from being saved in the Policy\Secrets\RasDialParams!SID#0 registry key. Microsoft has released a post SP5 hotfix that prevents these credentials from being cached. This hotfix can be found at
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/Hotfixes-PostSP5/RASPassword-fix/ or
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/Hotfixes-PostSP5/RRASPassword-fix/
Solution:
Microsoft has released a hotfix for NT 4.0 SP3 machines that prevents enumeration of the LSA secrets. This hotfix can be found at: ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/hotfixes-postSP3/lsa2-fix/
This hotfix has been included in Service Pack 4.
However, the LSA-2 patch does not prevent the username, phone number, and password from being saved in the Policy\Secrets\RasDialParams!SID#0 registry key. Microsoft has released a post SP5 hotfix that prevents these credentials from being cached. This hotfix can be found at
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/Hotfixes-PostSP5/RASPassword-fix/ or
ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/Hotfixes-PostSP5/RRASPassword-fix/
References
NT RAS Dial-up Networking "Save Password" Vulnerability
References:
References: