Server Operator password guessed |
---|
Risk Level: | High | Check or Attack Name: Guessed Server Operator Pwd |
---|---|---|
Platforms: | Windows NT | |
Description: | A Server Operator account has a password that has been guessed. Weak passwords allow attackers unauthorized access, including the ability to take over and replace processes, and access other computers on the network. |
|
Remedy: | Require users to use a minimum length for their passwords:
—AND— For maximum password security, apply the passfilt.dll password filter to prevent using a username as a password. See Microsoft Knowledge Base Article Q161990 "How to Enable Strong Password Functionality in Windows NT" at http://support.microsoft.com/support/kb/articles/q161/9/90.asp . |
|
References: |
Know Your Risks |