|
Firewalls (July 1996) |
> If I am not mistaken, if I sniff the encrypted password of > an NT user account, it is just as valuable to me as an > unencrypted one? Only if you can get the system requesting authorization to deliver it. To do this you would already have to have cracked the firewall. I don't think much of NT security, considering it mostly to be based on the obscurity of the NT code base, but in this case it's not a hole. References:
|