Forwarding Windows credentials for a client/server application
Brian Erdelyi <[email protected]> Wed, 11 Aug 2004 11:55:15 -0700 (PDT)
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
I have been analysing the authentication mechanisms of an application. The server component is on Unix and the client component is on Windows. I have discovered that the client component forwards the Windows user name of the currently logged on user to the server component. No authentication data is requested or sent. As a result, it is possible for me to install the client on a system and create a local Windows account that matches the user name of an existing user with access to the application. I can set my local password to anything. When the client starts on my system it forwards the username to the server and I am granted access. The computer does not need to be a member of the domain. Are there any Windows API's that the vendor can use with the client application to forward userid and password of the currently logged in user to the server component without prompting the user? Any recommendations that I could provide to the vendor? __________________________________ Do you Yahoo!? New and Improved Yahoo! Mail - 100MB free storage! http://promotions.yahoo.com/new_mail