Avoid Administrator password hacking ????

Avoid Administrator password hacking ????

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Avoid Administrator password hacking ???? serge calderara 07-01-2005
Posted by =?Utf-8?B?c2VyZ2UgY2FsZGVyYXJh on July 1, 2005, 3:42 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Dear all,

We are deploying to our worldwilde customers a set of application which is
installed on an standard industrial PC (we are delivery the same PC to all
our customer).

The system need to be stable and fully functionnal 24h/day.
For that we have issue a deployement security policy which is as follow:
- Administrator user has been rename to something else
- our customers can update any program on the system
- our customers can not install any windows update
- our customers cannot coonect the PC to they company Domain Controler
- Administrator password is know only by us for maintenance purpose

With this rules in place, we have a really stable and fully tested known
environment.
This to avoid library conflict as every developer is faced on each time

Unfortunatly, we have some customer which managed to hack administrator
password either by knowing it or by resetting it.

As far as I know tools that can be found on the internet can just reset the
password, or is there some which are able to show in clear text passwords?

If this occurs, which procedure can I put it place in order to block my
application if administartor password is changed ?

thnaks helping me to solve that issue
regard
serge


Posted by Susan Bradley, CPA aka Ebitz - on July 1, 2005, 3:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Physical access to a box means that you can easily reset the password

http://home.eunet.no/~pnordahl/ntpasswd/bootdisk.html

A contract with your client saying 'you void the warranty if you reset
the password'

However... "no updates?" Sir... I'd be having you sign a contract
saying within a reasonable about of time..say a day or so...that you'd
be patching that box. There's no way I'd let a vendor of mine determine
my patch status.

serge calderara wrote:

>Dear all,
>
>We are deploying to our worldwilde customers a set of application which is
>installed on an standard industrial PC (we are delivery the same PC to all
>our customer).
>
>The system need to be stable and fully functionnal 24h/day.
>For that we have issue a deployement security policy which is as follow:
> - Administrator user has been rename to something else
> - our customers can update any program on the system
> - our customers can not install any windows update
> - our customers cannot coonect the PC to they company Domain Controler
> - Administrator password is know only by us for maintenance purpose
>
>With this rules in place, we have a really stable and fully tested known
>environment.
>This to avoid library conflict as every developer is faced on each time
>
>Unfortunatly, we have some customer which managed to hack administrator
>password either by knowing it or by resetting it.
>
>As far as I know tools that can be found on the internet can just reset the
>password, or is there some which are able to show in clear text passwords?
>
>If this occurs, which procedure can I put it place in order to block my
>application if administartor password is changed ?
>
>thnaks helping me to solve that issue
>regard
>serge
>
>
>

--
An open letter to the Security Community::
http://msmvps.com/bradley/archive/2004/12/12/23540.aspx

Similar ThreadsPosted
RE: Administrator password June 20, 2005, 7:33 am
Administrator password June 14, 2005, 10:07 am
AD Administrator Password July 11, 2006, 12:20 pm
HOW CAN i GET THE ADMINISTRATOR PASSWORD? November 20, 2006, 7:41 am
HOW CAN i GET THE ADMINISTRATOR PASSWORD? November 20, 2006, 7:42 am
Administrator password March 16, 2007, 5:22 pm
Local Administrator Password December 22, 2005, 11:09 am
Change Administrator Password when expired November 28, 2005, 2:21 pm
Re: server 2003 administrator password June 12, 2005, 10:22 am
prevent to change Administrator password September 11, 2006, 7:45 am

The site map in XML format XML site map

Contact Us | Privacy Policy