Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NT Null Session Admin Name Vulnerability

By establishing a Null session with an NT host, an intruder can gain the name of even a renamed Administrator account. This is because even Null sessions are added to the Everyone group for the duration of the connection. This was done so that hosts not in the domain could still use MS Networking's browser functions.







 

Privacy Statement
Copyright 2009, SecurityFocus