Overview
Versions of SYSKEY in use prior to December, 1999 leave the SAM database vulnerable to cryptanalytic attacks.
Description
SYSKEY is a utility introduced in Microsoft Windows NT 4.0 service pack 3 to provide strong cryptographic protection to the SAM (password) database. The protection SYSKEY provides is intended to prevent attacks against the SAM database even if an intruder can obtain a copy of the database. Although the passwords stored in the SAM database are encrypted, if an intruder can obtain a copy of the SAM database, he can attempt a dictionary attack to obtain the passwords. That is, an intruder can select words from a dictionary, encrypt (or hash) them in the same way the SAM database would, and compare the results to the encrypted values stored in the SAM. If the values match, the intruder has discovered the password. Thwarting a dictionary attack is one of the reasons that you should choose a password that is not listed in any dictionary of any language.
|
Impact
Attackers can conduct dictionary attacks against the SAM database if they can obtain a copy of it. |
Solution
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://razor.bindview.com/publish/advisories/adv_WinNT_syskey.html
- http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms99-056.asp
- http://www.microsoft.com/technet/security/bulletin/fq99-056.asp
- http://www.securityfocus.com/templates/advisory.html?id=1974
- http://burks.bton.ac.uk/burks/foldoc/73/90.htm
- http://www.cs.uwf.edu/~wilde/CEN6990/papers/boone/RC4.htm
Acknowledgements
Our thanks to BindView's RAZOR team and Microsoft for the information in their advisories.
This document was written by Shawn V Hernan.
Other Information
CVE IDs: | CVE-1999-0994 |
Severity Metric: | 3.00 |
Date Public: | 1999-12-16 |
Date First Published: | 2001-11-15 |
Date Last Updated: | 2001-11-15 05:27 UTC |
Document Revision: | 5 |