CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
564 | CVE-1999-0582 | Candidate | A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. | Proposed (19990721) | ACCEPT(3) Ozancin, Shostack, Wall | MODIFY(2) Baker, Frech | REJECT(1) Northcutt | Northcutt> The definition is? | Baker> Maybe a rewording of this one too. I think most people would agree on | some "minimum" policies like 3-5 bad attempts lockout for an hour or | until the administrator unlocks the account. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for lockouts, e.g. lockout duration, | lockout after bad logon attempts, etc. | Ozancin> with reservations | What is appropriate? | Frech> XF:nt-thres-lockout | XF:nt-lock-duration | XF:nt-lock-window | XF:nt-perm-lockout | XF:lockout-disabled | View |
567 | CVE-1999-0585 | Candidate | A Windows NT administrator account has the default name of Administrator. | Proposed (19990721) | ACCEPT(1) Ozancin | MODIFY(1) Frech | REJECT(3) Baker, Northcutt, Shostack | REVIEWING(1) Wall | Wall> Some sources say this is not a vulnerability, but a warning. It just | slows down the search for the admin account (SID = 500) which can | always be found. | Northcutt> I change this on all NT systems I am responsible for, but is | root a vulnerability? | Baker> There are ways to identify the administrator account anyway, so this | is only a minor delay to someone that is knowledgeable. This, in and | of itself, doesn"t really strike me as a vulnerability, anymore than | the root account on a Unix box. | Shostack> (there is no way to hide the account name today) | Frech> XF:nt-adminexists | View |
595 | CVE-1999-0613 | Candidate | The rpc.sprayd service is running. | Proposed (19990721) | ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(1) Wall | REJECT(1) Northcutt | Frech> XF:sprayd | View |
351 | CVE-1999-0352 | Candidate | ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption. | Proposed (19990721) | ACCEPT(2) Baker, Frech | NOOP(2) Northcutt, Wall | RECAST(1) Ozancin | Ozancin> Can we combine this with CVE-1999-0356 - ControlIT(tm) 4.5 and earlier uses | weak encryption. | View |
607 | CVE-1999-0625 | Candidate | The rpc.rquotad service is running. | Proposed (19990721) | ACCEPT(3) Baker, Northcutt, Ozancin | MODIFY(1) Frech | NOOP(1) Wall | Frech> XF:rquotad | View |
Page 418 of 20943, showing 5 records out of 104715 total, starting on record 2086, ending on 2090