Microsoft Win9x Challenge Replay...

- AV AC AU C I A
发布: 1999-01-05
修订: 2025-04-13

The L0pht identified a weakness in Microsoft's Win9x authentication mechanism whereby the Win9x server issues the same cryptographic challenge for up to fifteen minutes. In a typical NT to Win9x authentication process, the Win9x server issues a challenge that is used by the NT server to encrypt the LanMan hash. The challenge-encrypted LanMan hash, along with the proper username, will grant an authorized user access to given resources on the Win9x server. Should an unauthorized user "sniff" the challenge-response sequence of a valid NT-Win9x login, he or she may replay this string from their own host to gain access to the Win9x server without knowledge of the clear-text password.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息