User account has blank password |
---|
Risk Level: | High | Check or Attack Name: accountblankpw |
---|---|---|
Platforms: | Windows NT | |
Description: | An account has been detected with a blank password. Some vendors ship Windows NT pre-installed with a blank password on the Administrator or other user accounts. This misconfiguration is an extremely high risk vulnerability, and should be corrected immediately. This vulnerability is typically detected on a machine where there is also no minimum password length required. If the Guest account has a blank password, it will allow anyone to log in with any user name and a blank password. If the file and registry permissions are not very tightly restricted, this situation can give any attacker the ability to access sensitive information and systems. |
|
Remedy: | Set the user password to a minimum length of seven characters and change the password. Require a minimum length for all passwords, or set up a password filter to reject weak password choices. Disable the account if is not required. To set the minimum password length, follow these steps:
—AND— For maximum password security, apply the passfilt.dll password filter to reduce guessable passwords. See Microsoft Knowledge Base Article Q161990 "How to Enable Strong Password Functionality in Windows NT" at http://support.microsoft.com/support/kb/articles/q161/9/90.asp. —OR— Disable the user account if it is not needed: To disable a user account, follow these steps:
|
|
References: |
Know Your Risks |