|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Win NT 4.0 UserId and Password available in memory
- To: NTBUGTRAQ
LISTSERV.NTBUGTRAQ.COM - Subject: Re: Win NT 4.0 UserId and Password available in memory
- From: Dominique Brezinski <dom_brezinski
SECURECOMPUTING.COM> - Date: Tue, 15 Dec 1998 15:55:55 -0800
- Approved-By: Russ.Cooper
RC.ON.CA - In-Reply-To: <3.0.3.32.19981215113310.076b1520
mail.mindspring.com> - References: <199812090513.XAA23310
sphinx.sctc.com> <199812050502.XAA10527
sphinx.sctc.com> <3.0.3.32.19981202091548.036abc30
mail.mindspring.com> <C12566CD.00485E7F.00
ZurichNotes.com> - Reply-To: Dominique Brezinski <dom_brezinski
SECURECOMPUTING.COM> - Sender: Windows NT BugTraq Mailing List <NTBUGTRAQ
LISTSERV.NTBUGTRAQ.COM>
At 11:33 AM 12/15/98 -0500, David LeBlanc wrote: >Someone told _you_ that you didn't know anything about security? ROTFL. You try to help out and learn while your doing it. You are going to make mistakes, and believe me I have plenty of times in public forums. People are going to be snappy and give you a little poke when you are wrong - that is the nature of techie people (myself included). But, some people just suck, and instead of poking you they yell about how stupid and wrong you are. Those kinds of people just better be damn sure they are right! >However, I do have somewhat of a disagreement with your position. As you >very well know, when we break into one machine at admin level, we'd like to >be able to leverage that to gain access to other systems. So making it >more difficult for one admin to become another user is of some benefit. >We'd especially like to make it more difficult for people to make that jump >using methods which we can't easily audit. I do agree, and there is probably no good reason for the password to be stored in plaintext in memory. Ideally it is not there, but you know my point was that it is not a security threat leveraged by un-trusted users. Your point starts getting into the area of how to provide robust security in a hostile environment. Unfortunately, I have to agree with the paper "The Inevitability of Failure: The Flawed Assumption of Security in Modern Computing Environments" in that we can not provide truly robust security with discretionary security controls that exist in current commercial operating systems. >One other point which I'd like to add is that now that we know that this >information is kept in clear-text, we may be able to develop ways to get to >it using some other method than just opening the process like we're >supposed to. That's worth a bit of examination. We're clearly not looking >at the newest gaping NT hole, but this isn't something I feel comfortable >completely dismissing, either. Nor do I, and I was a bit hard-lined and frustrated in my post. I don't think there is any good reason for the plaintext to exist in the process space, so it probably shouldn't. At the same time, the risk of it being there is of little consequence when the whole architectural model is taken into account. I rather see MS spend time and money putting assured mandatory security controls into NT than fixing this issue. The difference between 5 minutes of work and 75 man years of work is pretty great though ;) You know me - I could talk forever about a myriad of issues surrounding all this stuff, but I going to shut up now! Dominique Brezinski CISSP (206) 898-8254 Secure Computing http://www.securecomputing.com
- References:
- Re: Win NT 4.0 UserId and Password available in memory
- From: Dominique Brezinski <dom_brezinski
SECURECOMPUTING.COM>
- From: Dominique Brezinski <dom_brezinski
- Re: Win NT 4.0 UserId and Password available in memory
- From: Dominique Brezinski <dom_brezinski
SECURECOMPUTING.COM>
- From: Dominique Brezinski <dom_brezinski
- Re: Win NT 4.0 UserId and Password available in memory
- From: David LeBlanc <dleblanc
MINDSPRING.COM>
- From: David LeBlanc <dleblanc
- Win NT 4.0 UserId and Password available in memory
- From: russell.osterlund
ZURICH.COM
- From: russell.osterlund
- Re: Win NT 4.0 UserId and Password available in memory
- From: David LeBlanc <dleblanc
MINDSPRING.COM>
- From: David LeBlanc <dleblanc
- Re: Win NT 4.0 UserId and Password available in memory
- Prev by Date: Small problem in Shockwave
- Next by Date: Attacking "protected" machines through MS-Proxy Server 2.0.
- Prev by thread: Re: Win NT 4.0 UserId and Password available in memory
- Next by thread: Re: Win NT 4.0 UserId and Password available in memory
- Index(es):