NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability
BID:87
Info
NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability
| Bugtraq ID: | 87 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | May 05 1998 12:00AM |
| Updated: | May 05 1998 12:00AM |
| Credit: | |
| Vulnerable: |
Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability
Service Pack 3 added the ability to restrict anonymous users from obtaining information about the system. Even with SP3 installed anonymous users are able to retrieve the systems password policy.
Normally Windows NT uses anonymous access to the password policy to provide users with meaningful error message such as in the case of when an user changes his password before login in.
Service Pack 3 added the ability to restrict anonymous users from obtaining information about the system. Even with SP3 installed anonymous users are able to retrieve the systems password policy.
Normally Windows NT uses anonymous access to the password policy to provide users with meaningful error message such as in the case of when an user changes his password before login in.
Exploit / POC
NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability
References:
References: