Domain Guest has no password |
---|
Risk Level: | Medium | Check or Attack Name: Domain Guest No Pwd |
---|---|---|
Platforms: | Windows NT | |
Description: | A Domain Guest account has been detected with no password required. No password requirement allows attackers unauthorized access, including the ability to take over and replace processes, and access other computers on the network. |
|
Remedy: | Make sure all new users are created with an initial, random password. Disable the user account if it is not needed. To change a user's password, follow these steps:
—AND— Require that users must use a minimum length for their passwords. To change a password's length, follow these steps:
—AND— For maximum password security, apply the passfilt.dll password filter to reduce guessable passwords. —OR— Disable the user account if it is not needed. To disable a user account, follow these steps:
|
|
References: | Microsoft Knowledge Base Article Q161990, How to Enable Strong Password Functionality in Windows NT, http://support.microsoft.com/support/kb/articles/q161/9/90.asp |
Know Your Risks |