Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NT Anonymous Users Can Obtain The Password Policy Under Windows NT 4.0 Vulnerability

Service Pack 3 added the ability to restrict anonymous users from obtaining information about the system. Even with SP3 installed anonymous users are able to retrieve the systems password policy.

Normally Windows NT uses anonymous access to the password policy to provide users with meaningful error message such as in the case of when an user changes his password before login in.







 

Privacy Statement
Copyright 2009, SecurityFocus