Guest account has no password

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: guestnopw

Platforms: Windows NT
Description:

A Guest account with no password has been detected. An attacker could use this account to gain access to sensitive information.

Remedy:

Set the guest password to a minimum length of seven characters and change the password.

To set the minimum password length, follow these steps:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. Select Guest.
  3. From the Policies menu, select Account.
  4. Under Minimum Password Length, set the minimum length to at least seven characters.
  5. Click OK.

—AND—

To change the password, follow these steps:

  1. Open User Manager. From the Windows NT Start menu, select Programs, Administrative Tools (Common), User Manager.
  2. Select Guest.
  3. From the User menu, select Properties to display the User Properties dialog box.
  4. Under Password, change the password.
  5. Under Confirm Password, confirm the password.
  6. Click OK.

—AND—

For maximum password security, apply the passfilt.dll password filter to reduce guessable passwords.

References:

Microsoft Knowledge Base Article Q161990, How to Enable Strong Password Functionality in Windows NT, http://support.microsoft.com/support/kb/articles/q161/9/90.asp


X-Force Logo
Know Your Risks