Home » Hacking News » Microsoft WINS Domain Controller Spoofing Vulnerability
[Exploit]
Microsoft WINS Domain Controller Spoofing Vulnerability
by Phiber on January 19th, 2001 WINS does not properly verify the registration of domain controllers. It is possible for a user to modify the entries for a domain controller, causing the WINS service to redirect requests for the DC to another system. This can lead to a loss of network functionality for the domain. The DC impersonator can also be set up to capture username and password hashes passed to it during login attempts.[Exploit]