Disabled account username same as password |
---|
Risk Level: | Medium | Check or Attack Name: Disabled Account User Pwd |
---|---|---|
Platforms: | Windows NT | |
Description: | A disabled user account is using its username as the password. Weak passwords allow attackers unauthorized access, including the ability to take over and replace processes, and access other computers on the network. |
|
Remedy: |
Remove the user account if it is not needed. To remove a user account, follow these steps:
For maximum password security, apply the passfilt.dll password filter to prevent using a username as a password. See Microsoft Knowledge Base Article Q161990 "How to Enable Strong Password Functionality in Windows NT" at http://support.microsoft.com/support/kb/articles/q161/9/90.asp. |
|
References: |
Know Your Risks |