ms exchange server security

ms exchange server security

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
ms exchange server security BFM 06-29-2005
Posted by BFM on June 29, 2005, 4:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Just wondering how hard it would be to crack an exhange server email account
if I already have the username and only had to crack the password.(?)




Posted by Michael J. Pelletier on June 29, 2005, 10:04 am
If you were  Registered and logged in, you could reply and use other advanced thread options
BFM wrote:

> Just wondering how hard it would be to crack an exhange server email
> account if I already have the username and only had to crack the
> password.(?)

Certainly having the usernames is helpful...

Depends upon a couple of things

1) What is the password policy? How strong is it?
example: Is it required that passwords have uppercase and numbers?
2) How long is the aging policy? 30 days? 60, 90 days? Never?
3) Do I have access from the "outside" World (ie Internet access) in the
case where you allow authenticated email forwarding.

-Michael


Posted by Winged on June 29, 2005, 11:59 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
BFM wrote:
> Just wondering how hard it would be to crack an exhange server email account
> if I already have the username and only had to crack the password.(?)
>
>
If you don't have access to the server system files and a complex
password was used and you have big pipes and only 1 computer you should
be able to crack it in about 100,000 years or so. If the admins put a 3
missed trys on the password before it locks the account, it may take
somewhat longer. If complex password enforcement is not in place and
the administrators are complete idiots and did not set a max number of
tries before it locks the account...it is an indeterminable variable.

Bear in mind trying to brute force the account should ring off alarm
bells everywhere if even minimal security monitors are in place. A
decent network will lock you safely away from the server at the firewall
if you try cracking too hard. If there is any possibility that the
system is at all sensitive and business or governmental in nature, you
should be safely in jail long before you access the account.

There are far better ways to access exchange servers with much higher
probabilities of success.

Winged


Similar ThreadsPosted
exchange server problem December 19, 2006, 2:35 am
MS Exchange security June 29, 2005, 4:13 pm
Exchange AV question April 7, 2006, 1:25 pm
Microsoft patches Windows, Exchange flaws... May 11, 2006, 8:19 pm
Is this server secure enough? Is this server hackable? August 3, 2006, 1:45 pm
successfully installed openssl on hosted server - host says there i sno security unless I buy separate certificate - is that right? December 19, 2005, 3:44 pm
Locating a server March 5, 2006, 12:38 pm
ftp server question June 23, 2006, 8:27 am
How to secure a server? February 26, 2007, 11:01 am
more than only one certificate per server June 21, 2008, 7:44 am

The site map in XML format XML site map

Contact Us | Privacy Policy