Windows NT Network Monitor |
---|
Risk Level: | Medium | Check or Attack Name: Network Monitor |
---|---|---|
Platforms: | Windows NT | |
Description: | The Microsoft Network Monitor (NetMon) program has a weakly decrypted password in a DLL file. Access to this file would allow an attacker to gain access to the network monitor. |
|
Remedy: | Disable the Network Monitor Agent and remove the BHSUPP.DLL file from %systemroot%\system32. If the Network Monitor is required, use a hard to guess password. To disable the Network Monitor agent, follow these steps:
—AND— Remove BHSUPP.DLL from %systemroot%\system32. |
|
References: |
Know Your Risks |