Microsoft Site Server 3.0 Default Account Vulnerability
BID:3998
Info
Microsoft Site Server 3.0 Default Account Vulnerability
| Bugtraq ID: | 3998 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 1999 12:00AM |
| Updated: | Dec 21 1999 12:00AM |
| Credit: | Published in Microsoft KB article Q248840. |
| Vulnerable: |
Microsoft Site Server Commerce Edition 3.0 SP3 i386 Microsoft Site Server Commerce Edition 3.0 SP3 alpha Microsoft Site Server Commerce Edition 3.0 SP2 i386 Microsoft Site Server Commerce Edition 3.0 SP2 alpha Microsoft Site Server Commerce Edition 3.0 SP1 i386 Microsoft Site Server Commerce Edition 3.0 SP1 alpha Microsoft Site Server Commerce Edition 3.0 i386 Microsoft Site Server Commerce Edition 3.0 alpha Microsoft Site Server 3.0 SP3 i386 Microsoft Site Server 3.0 SP3 alpha Microsoft Site Server 3.0 SP2 i386 Microsoft Site Server 3.0 SP2 alpha Microsoft Site Server 3.0 SP1 i386 Microsoft Site Server 3.0 SP1 alpha Microsoft Site Server 3.0 i386 Microsoft Site Server 3.0 alpha |
| Not Vulnerable: |
Microsoft Site Server Commerce Edition 3.0 SP4 i386 Microsoft Site Server Commerce Edition 3.0 SP4 alpha Microsoft Site Server 3.0 SP4 i386 Microsoft Site Server 3.0 SP4 alpha |
Discussion
Microsoft Site Server 3.0 Default Account Vulnerability
Microsoft Site Server is designed to run on Microsoft Windows NT Server platforms. It provides a means for users on a corporate intranet to share, publish, and find information. Site Server Commerce Edition incorporates the same features as well as providing an interface for e-commerce sites to interact and conduct business with customers and suppliers.
By default, Site Server 3.0 the NT user account LDAP_Anonymous with a known password and local login privileges. In addition to local access, this may allow an attacker to exploit vulnerabilites such as BID 4000, 4002, 4004 and 4005.
Microsoft Site Server is designed to run on Microsoft Windows NT Server platforms. It provides a means for users on a corporate intranet to share, publish, and find information. Site Server Commerce Edition incorporates the same features as well as providing an interface for e-commerce sites to interact and conduct business with customers and suppliers.
By default, Site Server 3.0 the NT user account LDAP_Anonymous with a known password and local login privileges. In addition to local access, this may allow an attacker to exploit vulnerabilites such as BID 4000, 4002, 4004 and 4005.
Exploit / POC
Microsoft Site Server 3.0 Default Account Vulnerability
No exploit code is required to take advantage of this issue.
No exploit code is required to take advantage of this issue.
Solution / Fix
Microsoft Site Server 3.0 Default Account Vulnerability
Solution:
SP4 for Site Server 3.0 resolves this issue:
Microsoft Site Server 3.0 alpha
Microsoft Site Server Commerce Edition 3.0 SP2 i386
Microsoft Site Server Commerce Edition 3.0 SP2 alpha
Microsoft Site Server 3.0 SP1 alpha
Microsoft Site Server 3.0 SP2 alpha
Microsoft Site Server Commerce Edition 3.0 SP1 alpha
Microsoft Site Server 3.0 SP1 i386
Microsoft Site Server Commerce Edition 3.0 SP3 alpha
Microsoft Site Server 3.0 i386
Microsoft Site Server 3.0 SP3 alpha
Microsoft Site Server 3.0 SP3 i386
Microsoft Site Server Commerce Edition 3.0 i386
Microsoft Site Server Commerce Edition 3.0 SP3 i386
Microsoft Site Server 3.0 SP2 i386
Microsoft Site Server Commerce Edition 3.0 SP1 i386
Microsoft Site Server Commerce Edition 3.0 alpha
Solution:
SP4 for Site Server 3.0 resolves this issue:
Microsoft Site Server 3.0 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server Commerce Edition 3.0 SP2 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 SP2 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server 3.0 SP1 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server 3.0 SP2 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server Commerce Edition 3.0 SP1 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server 3.0 SP1 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 SP3 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server 3.0 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server 3.0 SP3 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE
Microsoft Site Server 3.0 SP3 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 SP3 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server 3.0 SP2 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 SP1 i386
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
Microsoft Site Server Commerce Edition 3.0 alpha
-
Microsoft Site Server 3.0 Service Pack 4 (Alpha)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-alpha.EXE -
Microsoft Site Server 3.0 Service Pack 4 (Intel)
http://download.microsoft.com/download/siteserver30/SP/sp4/NT45/EN-US/ ss3sp4-x86.EXE
References
Microsoft Site Server 3.0 Default Account Vulnerability
References:
References:
- Q248840: Possible Security Problem in LDAP_ANONYMOUS Account (Microsoft)
- Site Server Product Homepage (Microsoft)