NT "Pass the Hash" with Modified SMB Client Vulnerability

Solution:
In NT 4.0 Service Pack 4, Microsoft has added a Registry key and value that will prohibit an NT host from accepting LanMan authentication.

Add the "LMCompatibilityLevel" Value with a Value Type "REG_DWORD = 4" to the following Registry key:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\control\LSA

The Value Type 4 will prevent a Domain Controller (DC) from accepting LanMan authentication requests. The Microsoft knowledge base article Q147706 references Level 4 (and 5) for Domain Controllers. It is not known if this Value Type will prevent non-DCs (ie. NT workstations, member servers, and standalone servers) from accepting LanMan authentication.

There is no fix for NT versions prior to NT 4.0 SP4.



 

Privacy Statement
Copyright 2010, SecurityFocus