Domain User has no password |
---|
Risk Level: | High | Check or Attack Name: Domain User No Pwd |
---|---|---|
Platforms: | Windows NT | |
Description: | A Domain User account has been detected with no password required. No password requirement allows attackers unauthorized access to the host, including the ability to take over and replace processes, and access other computers on the network. |
|
Remedy: | Make sure all new users are created with an initial, random password:
—AND— Require users to use a minimum length for their passwords:
—AND— For maximum password security, apply the passfilt.dll password filter to reduce guessable passwords. |
|
References: | Microsoft Knowledge Base Article Q161990, How to Enable Strong Password Functionality in Windows NT, http://support.microsoft.com/support/kb/articles/q161/9/90.asp |
Know Your Risks |