Microsoft Windows SMB Last Logged On User Disclosure

info Nessus Plugin ID 38689

Synopsis

Nessus was able to identify the last logged on user on the remote host.

Description

By connecting to the remote host with the supplied credentials, Nessus was able to identify the username associated with the last successful logon.

Microsoft documentation notes that interactive console logons change the DefaultUserName registry entry to be the last logged-on user.

See Also

http://www.nessus.org/u?a29751b5

Plugin Details

Severity: Info

ID: 38689

File Name: smb_last_loggedon_user.nasl

Version: 1.12

Type: local

Agent: windows

Family: Windows

Published: 5/5/2009

Updated: 9/2/2019

Supported Sensors: Nessus Agent, Nessus

Vulnerability Information

Required KB Items: SMB/Registry/Enumerated, SMB/WindowsVersion