Note: This exploit can be accomplished by ANYONE that installs NT server
onto their computer. To perform my tests I used a barebones laptop,
installed NT server on it and found a network line at an open office in
my building to jack into, from there I was able to obtain user listings
from all other NT servers on the LAN without having to authenticate
myself to them!
For those of you that didn't see my first post on how this exploit works
here it is again:
1. Connect an NT server to the same network as the target NT
server.
2. From the USER MANAGER, create a trust relashionship with the
target. When prompted for a password, enter whatever you want; it
doesn't matter. You will get a response stating that NT couldn't verify
the trust (this is because of the invalid password). However, the
target will now be on your trusting list.
3. Launch NT Explorer and right click on any folder.
4. Select SHARING.
5. From the SHARED window, select ADD.
6. From the ADD menu, select your target NT server.
7. You will now see the entire group listing of the target. And if
you select SHOW USERS, you will see the entire user listing, including
full names and descriptions.
Comments are appreciated, maybe this should be considered a "non-issue"
and we should all just forget about it :).
Steve Thomas
Vice President of Operations
Innovative Protection Solutions
http://www.ips-corp.com/