Windows NT rlogin service installed |
---|
Risk Level: | Low | Check or Attack Name: ntrlogin |
---|---|---|
Platforms: | Windows NT | |
Description: | The Windows NT host is running the Ataman rlogin service. A user with a rlogin client could potentially compromise the machine's security with a brute force password attack. Also, this service could write sensitive information to the Windows NT Application Log. Typically, the application log does not contain information an attacker would find useful. However, some applications, such as the Ataman Telnet, Rlogin, and Rexec services, may write sensitive information to the application log. |
|
Remedy: | Disable rlogin if it is not needed or strengthen user name security by implementing strong password security and setting password restrictions in accordance with your security policy. To check and set the password policy, follow these steps:
To stop or disable the rlogin service in Windows NT, follow these steps:
|
|
References: |
Know Your Risks |