By default, Microsoft Site Server installs with a default password. The 'LDAP_Anonymous' account has a password of 'LdapPassword_1' which is publicly known and documented. This allows attackers to trivially access the system.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality
Solution:
Change Default Setting
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Technical
The password is hard coded into \winnt\system32\pNmsrvs.dll and \winnt\system32\inetsrv\dscomobj.dll. Thus, changing the password through the registry setting has no effect. It should also be noted that the system removes all traces after using this account.
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.
This product uses the Daylife API but is not endorsed or certified by Daylife.
This section lists the latest news and blogs found via the daylife API (and for older items, the technorati API), which mention or otherwise discuss this vulnerability.