CVE List

Id CVE No. Status Description Phase Votes Comments Actions
566  CVE-1999-0584  Candidate  A Windows NT file system is not NTFS.  Proposed (19990728)  ACCEPT(2) Northcutt, Wall | MODIFY(1) Frech | NOOP(2) Baker, Christey  Wall> NTFS partition provides the security. This could be re-worded | to "A Windows NT file system is FAT" since it is either NTFS or FAT | and FAT is less secure. | Frech> XF:nt-filesys(195) | Christey> MSKB:Q214579 | MSKB:Q214579 | http://support.microsoft.com/support/kb/articles/Q100/1/08.ASP  View
567  CVE-1999-0585  Candidate  A Windows NT administrator account has the default name of Administrator.  Proposed (19990721)  ACCEPT(1) Ozancin | MODIFY(1) Frech | REJECT(3) Baker, Northcutt, Shostack | REVIEWING(1) Wall  Wall> Some sources say this is not a vulnerability, but a warning. It just | slows down the search for the admin account (SID = 500) which can | always be found. | Northcutt> I change this on all NT systems I am responsible for, but is | root a vulnerability? | Baker> There are ways to identify the administrator account anyway, so this | is only a minor delay to someone that is knowledgeable. This, in and | of itself, doesn"t really strike me as a vulnerability, anymore than | the root account on a Unix box. | Shostack> (there is no way to hide the account name today) | Frech> XF:nt-adminexists  View
568  CVE-1999-0586  Candidate  A network service is running on a nonstandard port.  Proposed (19990728)  NOOP(1) Baker | RECAST(1) Shostack | REJECT(1) Northcutt  Shostack> Might be acceptable if clearer; is that a standard service on a | non-standard port, or any service on an unassigned port? | Baker> It might actually be an enhancement rather than a problem to run a service on a non-standard port  View
569  CVE-1999-0587  Candidate  A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.  Proposed (19990803)  ACCEPT(1) Wall | NOOP(1) Baker | RECAST(1) Northcutt  Northcutt> While I would accept this for Unix, I am not sure this applies to NT, | VMS, palm pilots, or commodore 64  View
570  CVE-1999-0588  Candidate  A filter in a router or firewall allows unusual fragmented packets.  Proposed (19990726)  MODIFY(2) Baker, Frech | REJECT(1) Northcutt  Northcutt> I want to vote to accept this one, but unusual is a shade broad. | Frech> XF:nt-rras | XF:cisco-fragmented-attacks | XF:ip-frag | Baker> Perhaps we should use the word abnormally fragmented or some other descriptor.  View

Page 114 of 20943, showing 5 records out of 104715 total, starting on record 566, ending on 570

Actions