Microsoft Windows XP Remote Desktop Plaintext Username Vulnerability
BID:3720
Info
Microsoft Windows XP Remote Desktop Plaintext Username Vulnerability
| Bugtraq ID: | 3720 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 19 2001 12:00AM |
| Updated: | Dec 19 2001 12:00AM |
| Credit: | Posted to the NTBugTraq mailing list by Tomasz Polus <[email protected]> on December 19, 2001. |
| Vulnerable: |
Microsoft Windows XP Professional Microsoft Windows XP Home |
| Not Vulnerable: | |
Discussion
Microsoft Windows XP Remote Desktop Plaintext Username Vulnerability
Microsoft Windows XP Remote Desktop transmits user account names in plain text over the network when a connection is initiated. The account name sent is not necessarily the user account name on the remote machine; it is the most recent user account used by the remote desktop client. A sniffer could potentially capture traffic on a network and discover user account names, especially when repeated connections are being made to a particular machine from Remote Desktop clients.
Microsoft Windows XP Remote Desktop transmits user account names in plain text over the network when a connection is initiated. The account name sent is not necessarily the user account name on the remote machine; it is the most recent user account used by the remote desktop client. A sniffer could potentially capture traffic on a network and discover user account names, especially when repeated connections are being made to a particular machine from Remote Desktop clients.
Exploit / POC
Microsoft Windows XP Remote Desktop Plaintext Username Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows XP Remote Desktop Plaintext Username Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows XP Remote Desktop Plaintext Username Vulnerability
References:
References:
- Windows XP security concerns (Tomasz Polus
)