Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Re: IE NTLM vulnerability?

Reply
Thread Tools Display Modes

Re: IE NTLM vulnerability?

 
 
Paul Baker [MVP, Windows Desktop Experience]
Guest
Posts: n/a

 
      12-21-2009
It could be using cached credentials and automatically logging in. You
already authenticated yourself when you logged in to Windows, so this might
be okay.

I would check your "User Authentication" settings for the zone.

Paul

"thathu" <> wrote in message
news:49841144-a0ee-44c3-8b6a-...
>I wrote a filter code on Tomcat to read the NTLM credentials from IE
> and do a Base 64 decode and get the user-id. I noticed that when I
> change IE NTLM settings to manually enter user-id and password, IE
> lets me through with any user-id and does not validate the login I
> enter against any source.
>
> Is this a security hole?



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Negotiate,NTLM. IE does not try NTLM after kerberos fails briend Internet Explorer 4 04-24-2010 04:56 PM
I also have an error 646 in Windows update. Please help. Jose Windows Update 12 01-09-2010 01:00 PM
WINDOWS UPDATE ERROR CODE 646 Lauracecilia Windows Update 13 12-10-2009 06:02 PM
Event ID 537- NTLM logon errors on SBS 2003 Simon Windows Small Business Server 1 11-09-2009 08:03 AM
Windows Server 2003 - How to stop it from usnig NTLM Engr Server Security 0 11-05-2009 11:16 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59