Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Focus on Microsoft
RE: [despammed] Defeating password cracking Feb 19 2003 08:50PM
Levinson, Karl (LevinsonK STARS-SMI com) (1 replies)
RE: [despammed] Defeating password cracking Feb 20 2003 12:18AM
dave (dave netmedic net)
Karl,

[snip]
If you haven't yet, I would want to test any new accounts and passwords that
you create to confirm whether you can use them in Recovery Console mode or
Directory Services Restore mode. My guess is if the character doesn't work
in L0phtcrack or a SAM-cracking utility, they very well might not work in
these modes... and that could leave you with a irreparable server when a
server disaster strikes.
[snip]

I have tested it with Recovery Console and yes it does work with the special
characters. I have not yet had the opportunity to test Directory Services
Restore. As soon as I do I will post my results.

So far I have tested this for use with the local system accounts, since that
is what the password recovery boot disks are usually used for. I will
experiment with it over network situations and application/exchange server
environments.

_____________________
Dave Kleiman
dave (at) netmedic (dot) net [email concealed]
www.netmedic.net

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus