Alnini.comUtilities » Security & Encryption » Windows 2000 Domain Account Lockout Vulnerability Patch
  

Windows 2000 Domain Account Lockout Vulnerability Patch MS00-089


This patch eliminates a security vulnerability in Microsoft Windows 2000. The vulnerability could allow a malicious user to use repeated attempts to guess an account password even if the domain administrator had set an account lockout policy.

A flaw in the way that NTLM authentication operates in Windows 2000 could allow a domain account lockout policy to be bypassed on a local Windows 2000 machine, even if the domain administrator had set such a policy. The ability of a malicious user to avoid the domain account lockout policy could increase the threat from a brute force password-guessing attack.

This vulnerability only affects Windows 2000 machines that are members of non-Windows 2000 domains. In addition, the vulnerability only affects domain user accounts that have previously logged into the target machine and already have cached credentials established on that machine. If a domain account lockout policy is in place and an attacker attempts a brute force password-guessing attack, the domain user account will be locked out as expected at the domain controller. However, if the attacker is able find the correct password, the local Windows 2000 machine will log the attacker on using cached credentials in violation of the account lockout policy. Although the attacker would be able to log on to the local machine, he or she would not be able to authenticate to the domain or gain access to resources on other machines in the domain.

Note: Windows 2000 Gold is not affected by this vulnerability. This patch will be included in Windows 2000 Service Pack 2. Domain Account Lockout vulnerability FAQ.

Publisher:

File size:

221KB

Date added:

28/11/2000

Licence:

Free

Un/Install:

No

Downloads:

1,564

Download Now!

See Also

Folder Lock 4.375

Lock, hide, and password-protect personal files, folders, and pictures from other users of your PC.

Primedius Firewall Lite 1.62

Prevent intrusions into your PC by hackers, spyware, and adware.

Real Spy Monitor 2.07

Monitor all keystrokes, programs used, and Web sites visited on a PC.

Partners
• 

RSS | FAQ |

Links | Maestro

Copyright © 2004-2023 Alnini, Inc. All Rights Reserved. Privacy Policy | Terms of UseGeneration time: 0.02 | SQL queries: 8