Guest user has blank password |
---|
Risk Level: | Medium | Check or Attack Name: guestblankpw |
---|---|---|
Platforms: | Windows NT | |
Description: | The Guest account has no password. Any individual can log in to this account with any user name and any password. This issue applies for both enabled and disabled Guest accounts. Although disabled accounts are less of a concern, an attacker may be able to enable the Guest account at a later time if they have already succeeded in compromising the network. |
|
Remedy: | Set the Guest password to a minimum length of seven characters and change the password. To set the minimum password length, follow these steps:
—AND— To change the password, follow these steps:
|
|
References: |
Know Your Risks |