Backup Operator username same as password

Risk Level: High risk vulnerability  High

Check or Attack Name: Backup Operator User Pwd

Platforms: Windows NT
Description:

A Backup Operator account was detected using its username as a password. Weak passwords allow attackers unauthorized access, including the ability to take over and replace processes, and access other computers on the network.

Remedy:

Disable the user account if it is not needed. To disable a user account, follow these steps:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. Select the user from the list.
  3. From the User menu, select Properties to display the User Properties dialog box.
  4. Select the Account Disabled check box.
  5. Click OK.

—OR—

For maximum password security, apply the passfilt.dll password filter to prevent using a username as a password. See Microsoft Knowledge Base Article Q161990 "How to Enable Strong Password Functionality in Windows NT" at http://support.microsoft.com/support/kb/articles/q161/9/90.asp.

References:

X-Force Logo
Know Your Risks