User account has no password |
---|
Risk Level: | High | Check or Attack Name: usernopw |
---|---|---|
Platforms: | Windows NT | |
Description: | A User account has been detected with no password required. No password requirement allows attackers unauthorized access, including the ability to take over and replace processes, and access other computers on the network. |
|
Remedy: | Set the user password to a minimum length of seven characters and change the password. To set the minimum password length, follow these steps:
—AND— To change the password, follow these steps:
—AND— For maximum password security, apply the passfilt.dll password filter to reduce guessable passwords. |
|
References: | Microsoft Knowledge Base Article Q161990, How to Enable Strong Password Functionality in Windows NT, http://support.microsoft.com/support/kb/articles/q161/9/90.asp |
Know Your Risks |