Password cache files accessible |
---|
Risk Level: | Medium | Check or Attack Name: nbsmbpwl |
---|---|---|
Platforms: | Windows for Workgroups: 3.11, Windows 95 | |
Description: | Windows 95, Windows for Workgroups, and DOS network clients cache passwords on the hard drive in files with the .PWL file extension. These password cache files are weakly encrypted and easily broken, and must not be accessible on a shared file system. In updated or patched versions of Windows 95, the encryption is stronger. |
|
Remedy: | Turn off file sharing on the host if it is not needed, or restrict sharing to the parts of the drive that are necessary to be shared. Apply the latest service patches for your operating system. Windows 95: Remove file and print sharing. To remove file and print sharing from Windows 95:
Windows NT: Perform the following actions: Apply the latest Windows NT 4.0 Service Pack:
—AND— Remove unnecessary shares. Choose one of these options:
|
|
References: | The NT Shop, Windows Client Password Caching Problems, http://www.ntsecurity.net/security/pswcache.htm |
Know Your Risks |