Re[2]: [Full-Disclosure] Automatically passing NTLM authentication credentials on Windows XP

2004-09-29 Thread Hidenobu Seki
From: 3APA3A <[EMAIL PROTECTED]> I don't think problem reported by you is different issue, it's just another exploit scenario for the same problem. I know few more tricks to redirect user to UNC share. I see your meaning. So, I agree. I hope Microsoft fundamentally address the issue in the fut

Re[2]: [Full-Disclosure] Automatically passing NTLM authentication credentials on Windows XP

2004-09-29 Thread 3APA3A
Dear Hidenobu Seki, HS> Tell me why Microsoft issued patches for MS00-067(KB272743) and HS> MS01-001(KB282132) but not for "img src". > 3APA3A or all I have same question. I had discussion on this topic with Microsoft security team again just few weeks ago (and 2 more discussions during l

Re: [Full-Disclosure] Automatically passing NTLM authentication credentials on Windows XP

2004-09-28 Thread Hidenobu Seki
From: 3APA3A <[EMAIL PROTECTED]> This problem is known since at least 1997 and still can be exploited with without any MS Word document. It is not true. They are different problems that happen the same phenomenon. Mr. Cesar Cerrudo taught me that still works. Tell me why Microsoft iss

Re: [Full-Disclosure] Automatically passing NTLM authentication credentials on Windows XP

2004-09-28 Thread Barrie Dempster
The originally posted link had this information on it. On Tue, 2004-09-28 at 14:17, 3APA3A wrote: > Dear Hidenobu Seki, > > This problem is known since at least 1997 and still can be exploited > with without any MS Word > document. > > --Tuesday, September 28, 2004, 2:20:13 AM, you wr

Re: [Full-Disclosure] Automatically passing NTLM authentication credentials on Windows XP

2004-09-28 Thread 3APA3A
Dear Hidenobu Seki, This problem is known since at least 1997 and still can be exploited with without any MS Word document. --Tuesday, September 28, 2004, 2:20:13 AM, you wrote to [EMAIL PROTECTED]: HS> Hello. HS> For your information: HS> Automatically passing NTLM authentication cr

[Full-Disclosure] Automatically passing NTLM authentication credentials on Windows XP

2004-09-27 Thread Hidenobu Seki
Hello. For your information: Automatically passing NTLM authentication credentials on Windows XP http://www.securityfriday.com/Topics/winxp3.html Thank you. _ Add photos to your messages with MSN 8. Get 2 months FREE*. http://join.msn