Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows >> SMB Registry : Classic Logon Screen


Vulnerability Assessment Details

SMB Registry : Classic Logon Screen

Vulnerability Assessment Summary
Acertains the value of a remote key

Detailed Explanation for this Vulnerability Assessment

Summary :

User lists is displayed locally.

Description :

The registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\WinLogon\LogonType
does not exist or is set to 1.

It means that users who attempt to log in locally will see get the
'new' WindowsXP logon screen which displays the list of users of the
remote host.

Solution :

Use regedt32 and set the value of this key to 0

Network Security Threat Level:

Low / CVSS Base Score : 1
(AV:L/AC:H/Au:R/C:P/A:N/I:N/B:C)

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors

DELL POWEREDGE R620 10 BAY TWO E5-2620V2 2.10GHZ 96GB 3 X 300GB 15K SAS H310
$1809.0
DELL POWEREDGE R620 10 BAY TWO E5-2620V2 2.10GHZ 96GB 3 X 300GB 15K SAS H310 pictureDELL POWEREDGE R720XD 3.5 SERVER TWO E5-2620V2 2.10GHZ 96GB 12 X 300GB 15K SAS 5
$4019.0
DELL POWEREDGE R720XD 3.5 SERVER TWO E5-2620V2 2.10GHZ 96GB 12 X 300GB 15K SAS 5 pictureDELL POWEREDGE R620 10 BAY TWO E5-2609 2.40GHZ 256GB 600GB 15K SAS H310
$3959.0
DELL POWEREDGE R620 10 BAY TWO E5-2609 2.40GHZ 256GB 600GB 15K SAS H310 pictureDELL POWEREDGE R620 10 BAY TWO E5-2650LV2 1.70GHZ 512GB 4 X 600GB 15K SAS H710P
$7839.0
DELL POWEREDGE R620 10 BAY TWO E5-2650LV2 1.70GHZ 512GB 4 X 600GB 15K SAS H710P picture


Discussions

No Discussions have been posted on this vulnerability.