Domain User username same as password |
---|
Risk Level: | High | Check or Attack Name: Domain User User Pwd |
---|---|---|
Platforms: | Windows NT | |
Description: | A Domain Administrator account has the same username as the password. Weak passwords allow attackers unauthorized access to the host, including the ability to take over and replace processes, and access other computers on the network. |
|
Remedy: | Disable the account if it is not needed. To disable an account, follow these steps:
For maximum password security, apply the passfilt.dll password filter to prevent using a username as a password. See Microsoft Knowledge Base Article Q161990 "How to Enable Strong Password Functionality in Windows NT" at http://support.microsoft.com/support/kb/articles/q161/9/90.asp . |
|
References: | Microsoft Knowledge Base Article Q161990, How to Enable Strong Password Functionality in Windows NT, http://support.microsoft.com/support/kb/articles/q161/9/90.asp |
Know Your Risks |