Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: Novell 32bit Client , Passwords

Re: Novell 32bit Client , Passwords

From: Seth R Arnold <sarnold_at_WILLAMETTE.EDU>
Date: Thu, 6 Apr 2000 10:18:32 -0700

* Michael Sanders <michaels_at_ebusolutions.co.za> [000406 08:42]:
> Sorry if this has been covered already, does anyone know were the passwords
> are cached in the novell client? Ive noticed that when a Novell 4.11 server
> goes down and brought back up again the client authenticates with the
> correct logon details to the NDS. Is they cached , are the encrypted adn do
> they get cleared ?

Michael, it might vary between the microsoft novell client and the
novell novell client (aka intranetware, aka client32) -- but I believe
both of them store the passwords in windows' .pwd files (under 9x) and
in user.dat in the user's profile directory under NT.

As for being encrypted, they are at least obfuscated. They might be
stored encrypted with the user's single-signon password, or they might
be stored in a plain-text equivalence. I honestly don't know, but a
search at MS's KB for "password cache" or "password caching" might turn
up exactly what you want to know.

HTH

--
Seth Arnold | http://www.willamette.edu/~sarnold/
Hate spam? See http://maps.vix.com/rbl/ for help
Received on Apr 06 2000
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos