Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Focus on Microsoft
Re: focus-ms (at) securityfocus (dot) com [email concealed] Aug 30 2003 08:49AM
fala83@libero.it (fala83 libero it) (5 replies)
Wasn't someone looking for a Group Policy collection tool? Oct 04 2003 02:48AM
Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net)
Re: focus-ms (at) securityfocus (dot) com [email concealed] Sep 02 2003 12:42PM
simonis (simonis myself com) (1 replies)
RE: focus-ms (at) securityfocus (dot) com [email concealed] Sep 02 2003 08:46PM
Kim Oppalfens (kimoppalfens tiscali be) (1 replies)
RE: focus-ms (at) securityfocus (dot) com [email concealed] Sep 04 2003 12:08AM
Paulo Wilbert (pwilbert uninet com br)
cached passwords (was RE: focus-ms (at) securityfocus (dot) com [email concealed]) Sep 02 2003 06:28AM
Zachary Mutrux (zmutrux compumentor org)
Re: focus-ms (at) securityfocus (dot) com [email concealed] Sep 02 2003 01:11AM
Sam Baskinger (sam reefedge com)
Re: focus-ms (at) securityfocus (dot) com [email concealed] Sep 01 2003 08:23PM
Flávio Pereira (fpereirabr yahoo com br)
I think that you can create users/Groups with
different privilege level.
Then, try to insert this users in differents
Security policy.
I agree that Users and password cannot be locally
cached but when have LapTop users, It's necessary.

--- "fala83 (at) libero (dot) it [email concealed]" <fala83 (at) libero (dot) it [email concealed]> escreveu: >
In my opinion a system wouldn'n cache password
> locally.
> E.g. Sysadmin logs in into a workstation and
> password will be stored locally. An
> attacker could retrieve his password and login into
> the whole network whit
> administrative privileges. It is not completely
> safe.
> I'd rather prefer use Kerberos, using his tickets to
> access network resource
> without caching password.
> Anyway if the password must be stored locally, it
> must be!
>
>
> >Todd Shubert wrote:
> >
> > What exactly is the "right security policy"?
> Wouldn't not storing the
> > password provide problems for users, specifically
> laptop users, that
> > require the use of cached credentials?
>
>
>
------------------------------------------------------------------------
---
> KaVaDo provides the first and only integrated Web
> application scanner and
> firewall security suite that prevent Web
> applications attacks, the most
> common form of online exploitation. Download a FREE
> whitepaper on Security Policy Automation for Web
> Applications.
>
http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
>
------------------------------------------------------------------------
---
>

=====

Flávio Pereira

ICQ 62382441

flavio_it (at) hotmail (dot) com [email concealed] (MSN)

fpereirabr (at) yahoo.com (dot) br [email concealed]

Cel.: 9730-6277

_______________________________________________________________________
Desafio AntiZona: participe do jogo de perguntas e respostas que vai
dar um Renault Clio, computadores, câmeras digitais, videogames e muito
mais! www.cade.com.br/antizona

------------------------------------------------------------------------
---
KaVaDo provides the first and only integrated Web application scanner and
firewall security suite that prevent Web applications attacks, the most
common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
------------------------------------------------------------------------
---

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus