Domain Administrator account has blank password

Risk Level: High risk vulnerability  High

Check or Attack Name: Domain Admin Blank Pwd

Platforms: Windows NT
Description:

A Domain Administrator user account has been detected with a blank password. Blank passwords allow attackers unauthorized access, including the ability to take over and replace processes, and access other computers on the network.

Remedy:

Set the user password to a minimum length of seven characters and change the password. Require a minimum length for all passwords, or set up a password filter to reject weak password choices. Disable the account if is not required.

To set the minimum password length, follow these steps:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. Select the user account from the list.
  3. From the Policies menu, select Account to display the Account Policy dialog box.
  4. For the Minimum Password Length, require a minimum length of at least seven characters. Click OK.
  5. From the User menu, select Properties to display the User Properties dialog box.
  6. Type and confirm a non-trivial password.
  7. Click OK.

—AND—

For maximum password security, apply the passfilt.dll password filter to reduce guessable passwords. See Microsoft Knowledge Base Article Q161990 "How to Enable Strong Password Functionality in Windows NT" at http://support.microsoft.com/support/kb/articles/q161/9/90.asp.

—OR—

Disable the user account if it is not needed:

To disable a user account, follow these steps:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. Select the user from the list.
  3. From the User menu, select Properties to display the User Properties dialog box.
  4. Select the Account Disabled check box.
  5. Click OK.
References:

X-Force Logo
Know Your Risks