NetUserModalsGet() and NT/Win2K Password Policy retrieval tool
------------------------------------------------------------------------


DETAILS

A Win32 networking API called NetUserModalsGet() requires no 
authentication, just the establishment of a NULL NetBIOS session. This
API 
function can be used to get the system-wide password policy information 
(intruder lockout, the depth of the password history, minimum password 
length requirements, the name of the PDC, and so forth) from Windows NT 
and Windows 2000 machines. Because it's RPC-based, like all the net 
functions, it can be executed remotely (providing the relevant ports are 
not blocked by an intermediate router or firewall).

A tool called ChkLock is available to use this function and retrieve 
sensitive information from remote computers.

There is also a very good technical article about this API command, and 
other similar commands, and on the subject of NULL sessions:
 <http://www.berbee.com/security/techover.html> 
http://www.berbee.com/security/techover.html


ADDITIONAL INFORMATION

ChkLock can be downloaded from:
 <http://www.berbee.com/security/chklock.html> 
http://www.berbee.com/security/chklock.html

--
Eko Sulistiono
MIKRODATA & AntiVirus Media
Web: http://www.mikrodata.co.id/
WAP: http://www.mikrodata.co.id/wap/index.wml

This message contains no viruses. Guaranteed by AVP.


------------------------------------------------------------------------
Forum Komunikasi Penulis-Pembaca MIKRODATA (FKPPM)

Informasi : http:[EMAIL PROTECTED]
Arsip     : http://www.mail-archive.com/forum%40mikrodata.co.id/
WAP       : http://mikrodata.co.id/wap/index.wml

Milis ini menjadi kontribusi beberapa rubrik yang diasuh tim MIKRODATA.
Termasuk rubrik-rubrik yang ada di media lain.

Memakai, Menyebarluaskan, dan Memperbanyak software bajakan adalah 
tindakan kriminal.

Please check with the latest AVP update before you ask about virus:
ftp://mikrodata.co.id/avirus_&_security/AntiViral_Toolkit_Pro/avp30.zip

Kirim email ke