LSA registry key altered |
---|
Risk Level: | High | Check or Attack Name: ntpwdll |
---|---|---|
Platforms: | Windows NT | |
Description: | This system was found with an altered LSA registry key. This setting may allow access in plaintext to all new passwords. Changing passwords or adding users calls the security provider with the userid and plaintext password. If an unauthorized security provider has been installed, all accounts information may have been re-routed in plaintext to an unauthorized location. |
|
Remedy: | Set write permissions to Administrators or System, or remove the FPNWCLNT.DLL security provider program. To set permissions for the ACL key, follow these steps:
To remove the FPNWCLNT value, follow these steps:
|
|
References: |
Know Your Risks |