Select the product you need help with
OFF2000: No Prompt Opening Web Folder with Internet Explorer Security Set for Logon PromptArticle ID: 282132 - View products that this article applies to. This article was previously published under Q282132 On This PageSYMPTOMS When you open a Web folder or a Network Place to a location
on the Internet or an intranet, there is no logon prompt that requests your
user name and password. This occurs even though you configure your Microsoft
Internet Explorer security settings to prompt for your user name and password.
CAUSE This problem occurs when the following conditions are
true:
RESOLUTIONTo resolve this problem, obtain the latest service
pack for Windows 2000. For additional information, click the following article
number to view the article in the Microsoft Knowledge Base: 260910 Microsoft has released a patch that eliminates a
security vulnerability in a component that is included with Microsoft Office
2000, Windows 2000, and Windows Me. Download and install the appropriate patch,
according to your situation listed later in this article.
(http://support.microsoft.com/kb/260910/EN-US/
)
How to Obtain the Latest Windows 2000 Service Pack
If an Office 2000 Family Product Is Installed on Your ComputerTo resolve this problem, obtain the latest service pack for Microsoft Office 2000. For additional information, click the following article number to view the article in the Microsoft Knowledge Base:276367
(http://support.microsoft.com/kb/276367/EN-US/
)
OFF2000: How to Obtain the Latest Office 2000 Service PackIMPORTANT: Before you install Microsoft Office 2000 Service Pack 3 (SP-3), you must have Microsoft Office 2000 Service Release 1/1a (SR-1/SR-1a) installed first. To obtain Office 2000 Service Release 1/1a (SR-1/SR-1a), click the article number below to view the article in the Microsoft Knowledge Base: 245025
(http://support.microsoft.com/kb/245025/EN-US/
)
OFF2000: How to Obtain and Install Microsoft Office 2000 Service Release 1/1a (SR-1/SR-1a)
This problem was first corrected in the Web Client Security Update for Office 2000. For additional information about how to obtain and install this update, click the article number below to view the article in the Microsoft Knowledge Base: 285338
(http://support.microsoft.com/kb/285338/EN-US/
)
OFF2000: Web Client Security Update for Office 2000 Available
If Your Operating System Is Windows Millennium Edition Without an Office 2000 Family Product InstalledTo correct this problem, follow these steps to download and install the Web Extender Client (WEC) Security Update for Windows Me from the Microsoft Download Center:
119591 Microsoft scanned this file for viruses. Microsoft used the most
current virus-detection software that was available on the date that the file
was posted. The file is stored on security-enhanced servers that help to
prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
If Your Operating System Is Windows 2000 Without an Office 2000 Family Product InstalledTo correct this problem, follow these steps to download and install the Windows 2000 Security Patch from the Microsoft Download Center:
119591 Microsoft scanned this file for viruses. Microsoft used the most
current virus-detection software that was available on the date that the file
was posted. The file is stored on security-enhanced servers that help to
prevent any unauthorized changes to the file.
(http://support.microsoft.com/kb/119591/EN-US/
)
How to Obtain Microsoft Support Files from Online Services
STATUSMicrosoft
has confirmed that this is a problem in the Microsoft products that are listed
at the beginning of this article.
This problem was first corrected in Windows 2000 Service
Pack 2. This problem has been fixed in the Microsoft Web Client
Security Updates. MORE INFORMATION The Web Extender Client (WEC) is a component that is
included with Office 2000, Windows 2000, and Windows Me. WEC permits Internet
Explorer to view and publish files by means of Web folders, similar to viewing
and adding files in a directory through Windows Explorer. Because of an
implementation flaw, WEC does not respect the Internet Explorer Security
settings regarding when NTLM authentication is to be performed. Instead, WEC
performs NTLM authentication with any server that requests it. If a user
establishes a session with a malicious user's Web site, either by browsing to
the site or by opening an HTML e-mail that initiates a session with it, an
application on the site could capture the user's NTLM credentials. The
malicious user could then use an offline brute force attack to derive the
password, or, with specialized tools, could submit a variant of these
credentials in an attempt to access protected resources. The vulnerability would only provide the malicious user with the cryptographically protected NTLM authentication credentials of another user. It would not, by itself, permit a malicious user to gain control of another user's computer or to gain access to resources to which that user has authorized access. To use the NTLM credentials (or a subsequently cracked password), the malicious user would have to be able to remotely log on to the target system. However, best practices dictate that remote logon services be blocked at border devices, and if these practices are followed, they would prevent an attacker from using the credentials to log on to the target system. For more information about the Web Client Security Update for Office 2000, please visit the following Microsoft Security Bulletin: http://www.microsoft.com/technet/security/bulletin/MS01-001.mspx
(http://www.microsoft.com/technet/security/bulletin/MS01-001.mspx)
An Example of the Problem
How to Determine That the Patch Is InstalledNote that the Fp4awec.dll file in the Program Files\Common Files\Microsoft Shared\Web Server Extensions\40\bin folder is updated to version 4.0.2.4715 after the Web Client Security Update for Office 2000 is installed. Right-click the Fp4awec.dll file from Windows Explorer, and then click the Version tab to confirm the version information.PropertiesArticle ID: 282132 - Last Review: July 16, 2007 - Revision: 5.9 APPLIES TO
|


Back to the top








