Password history length insufficient

Risk Level: Low risk vulnerability  Low

Check or Attack Name: Password History

Platforms: Windows NT
Description:

The password history length is less than the specified security policy. Windows NT will prevent a user from reusing the number of passwords specified by the password history length.

Remedy:

Set the password history length value so that it equals or exceeds the value in the current policy.

To change the password history value, follow these steps:

    1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
    2. From the Policies menu, select Account to display the Account Policy dialog box.
    3. In the Password Uniqueness box, set the value to remember to at least the value specified by the current policy.
    4. Click OK.
  • References:

    X-Force Logo
    Know Your Risks