Free Downloads Center
e.g. Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability MS01-001

Categories

Latest Reviews

Asterix and the Great Rescue

Asterix and the Great Rescue
Asterix and the Great Rescue is a fun and fanciful game suitable to all ages with an addictive game-play.

Proposalsmartz Proposal Writing Software

Proposalsmartz Proposal Writing Software
Proposalsmartz Proposal Writing Software is an handy application that allows you to work about smartly with your business proposals and documents.

Subscribe

Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability MS01-001 Download

Editor's rating  
Users' rating   (0 votes) Rate it!
License Freeware /
Downloads 1745
Publisher Microsoft Corp.
File size 312K
Date added 15-Jan-2001
Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability screenshot

Enlarge screenshot

Publisher's description
Submit your review

The Web Extender Client (WEC) is a component that ships as part of Office 2000, Windows 2000, and Windows Me. WEC allows IE to view and publish files via web folders, similar to viewing and adding files in a directory through Windows Explorer. Due to an implementation flaw, WEC does not respect the IE Security settings regarding when NTLM authentication will be performed – instead, WEC will perform NTLM authentication with any server that requests it. If a user established a session with a malicious user’s web site – either by browsing to the site or by opening an HTML mail that initiated a session with it – an application on the site could capture the user’s NTLM credentials. The malicious user could then use an offline brute force attack to derive the password or, with specialized tools, could submit a variant of these credentials in an attempt to access protected resources. The vulnerability would only provide the malicious user with the cryptographically protected NTLM authentication credentials of another user. It would not, by itself, allow a malicious user to gain control of another user’s computer or to gain access to resources to which that user was authorized access. In order to leverage the NTLM credentials (or a subsequently cracked password), the malicious user would have to be able to remotely logon to the target system. However, best practices dictate that remote logon services be blocked at border devices, and if these practices were followed, they would prevent an attacker from using the credentials to logon to the target system. This download is for Windows ME (without Office 2000 installed).

Visit homepage of Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability

Download Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability MS01-001



access blocked site
user authentication
logon security
brute force dictionary attack
extract microsoft office files
dictate to computer
key logon
capture video windows
office remove password
web publish

Programs related to Microsoft Windows ME Security Patch: 'Web Client NTLM Authentication' Vulnerability

Copyright © 2001-2009, Free Downloads Center.