[4245] in bugtraq
Re: Netware + Win95 issue
daemon@ATHENA.MIT.EDU (Paul Melson)
Tue Apr 8 16:02:21 1997
Date: Tue, 8 Apr 1997 13:56:34 -0400
Reply-To: Paul Melson <melson@SCNC.HOLT.K12.MI.US>
From: Paul Melson <melson@SCNC.HOLT.K12.MI.US>
X-To: mauri@MBP.EE
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <6A98FA6BA8@nw1.mbp.ee> from Lauri Laupmaa at "Apr 7,
97 11:11:39 am"
> Hi
>
> There seems to be serious security flaw in win95 dealing with novell
> netware passwords. It's trivial to find netware password in win95
> swap file by just scanning the hard disk for USERNAME (with some disk
> editor) The only solution I have found is to disable virtual memory,
> but this is not a SOLUTION, because lot of programs just do not work
> without it...
>
> btw. I'm talking about MS netware client (not aware if this flaw is
> present in Novell client32)
By default, this problem is also present in the latest
(July 96) release of NetWare Client32 for Windows 95.
It can be disabled by going into the Network control
panel item, opening the "Novell NetWare Client 32
Properties" dialogue, and disabling the "Cache NetWare
Password" option on the "Advanced Options" page.
Paul
--
_____________________
melson@holt.k12.mi.us