|
Focus on Microsoft
Re: focus-ms (at) securityfocus (dot) com [email concealed] Aug 30 2003 08:49AM fala83@libero.it (fala83 libero it) (5 replies) Wasn't someone looking for a Group Policy collection tool? Oct 04 2003 02:48AM Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net) Re: focus-ms (at) securityfocus (dot) com [email concealed] Sep 02 2003 12:42PM simonis (simonis myself com) (1 replies) RE: focus-ms (at) securityfocus (dot) com [email concealed] Sep 02 2003 08:46PM Kim Oppalfens (kimoppalfens tiscali be) (1 replies) RE: focus-ms (at) securityfocus (dot) com [email concealed] Sep 04 2003 12:08AM Paulo Wilbert (pwilbert uninet com br) Re: focus-ms (at) securityfocus (dot) com [email concealed] Sep 02 2003 01:11AM Sam Baskinger (sam reefedge com) Re: focus-ms (at) securityfocus (dot) com [email concealed] Sep 01 2003 08:23PM Flávio Pereira (fpereirabr yahoo com br) |
|
|
Privacy Statement |
you are a sysadmin.
http://support.microsoft.com/default.aspx?scid=kb;en-us;172931
zm
> -----Original Message-----
> From: fala83 (at) libero (dot) it [email concealed] [mailto:fala83 (at) libero (dot) it [email concealed]]
> Sent: Saturday, August 30, 2003 1:50 AM
> To: focus-ms; todd
> Subject: Re: focus-ms (at) securityfocus (dot) com [email concealed]
>
>
> In my opinion a system wouldn'n cache password locally.
> E.g. Sysadmin logs in into a workstation and password will be
> stored locally. An
> attacker could retrieve his password and login into the whole network whit
> administrative privileges. It is not completely safe.
> I'd rather prefer use Kerberos, using his tickets to access
> network resource
> without caching password.
> Anyway if the password must be stored locally, it must be!
>
> >Todd Shubert wrote:
> >
> > What exactly is the "right security policy"? Wouldn't not storing the
> > password provide problems for users, specifically laptop users, that
> > require the use of cached credentials?
>
>
> ------------------------------------------------------------------
> ---------
> KaVaDo provides the first and only integrated Web application scanner and
> firewall security suite that prevent Web applications attacks, the most
> common form of online exploitation. Download a FREE whitepaper on
> Security Policy Automation for Web Applications.
> http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
> ------------------------------------------------------------------
> ---------
>
>
------------------------------------------------------------------------
---
KaVaDo provides the first and only integrated Web application scanner and
firewall security suite that prevent Web applications attacks, the most
common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
------------------------------------------------------------------------
---
[ reply ]