|
NT "Pass the Hash" with Modified SMB Client Vulnerability
Solution: In NT 4.0 Service Pack 4, Microsoft has added a Registry key and value that will prohibit an NT host from accepting LanMan authentication. Add the "LMCompatibilityLevel" Value with a Value Type "REG_DWORD = 4" to the following Registry key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\control\LSA The Value Type 4 will prevent a Domain Controller (DC) from accepting LanMan authentication requests. The Microsoft knowledge base article Q147706 references Level 4 (and 5) for Domain Controllers. It is not known if this Value Type will prevent non-DCs (ie. NT workstations, member servers, and standalone servers) from accepting LanMan authentication. There is no fix for NT versions prior to NT 4.0 SP4. |
|
|
Privacy Statement |