Click here to get back home

Admin password recovery; LockSmith? Risk?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Admin password recovery; LockSmith? Risk? Michael 02-09-2006
Posted by Michael on February 9, 2006, 10:12 pm
Please log in for more thread options
Hi all,
I've noticed on the web that there are numerous "password recovery" tools
available. It appears to be relatively easy to brute force "replace"
administrator account's password within minutes.

Now I really hope those recovered passwords are at best only the LOCAL
Administrator account. What if the server is an AD domain controller, does
that mean those tools actually could recover a "domain administrator"
account's password?

Is it that easy for such tools (like locksmith) to replace a domain
administrator password that I believe resides a highly encrypted "ntds.dit"
AD db file?

If this password recovery is so easy, that'll spell big trouble for DC at
some smaller branches that might not be as physically secure as the HQ
sites. We are currently using Windows Server 2003 SP1 DCs and soon to update
them with R2.

Looking forward to some reality checks and pointers.

Cheers, and thanks.



Posted by RJ on February 9, 2006, 11:36 pm
Please log in for more thread options
Yes, it is that easy. But don't forget, MS, as well as other software/
harware vendors, say physical security is just as important as any other
security precaution.

If you don't / can't limit physical access to your servers, network equipment,
databases and so on... then you are leaving yourself open to intrusion.

Time to start locking the door on the server room... oh, wait, you don't
have a locked door... time to get one.



> Hi all,
> I've noticed on the web that there are numerous "password recovery" tools
> available. It appears to be relatively easy to brute force "replace"
> administrator account's password within minutes.
>
> Now I really hope those recovered passwords are at best only the LOCAL
> Administrator account. What if the server is an AD domain controller, does
> that mean those tools actually could recover a "domain administrator"
> account's password?
>
> Is it that easy for such tools (like locksmith) to replace a domain
> administrator password that I believe resides a highly encrypted "ntds.dit"
> AD db file?
>
> If this password recovery is so easy, that'll spell big trouble for DC at
> some smaller branches that might not be as physically secure as the HQ
> sites. We are currently using Windows Server 2003 SP1 DCs and soon to update
> them with R2.
>
> Looking forward to some reality checks and pointers.
>
> Cheers, and thanks.
>
>



Similar ThreadsPosted
Problem in Change Password! Password Recovery August 27, 2005, 1:24 am
Earn money Online - without risk! December 24, 2005, 10:13 pm
Possible compromise of Windows Server 2003 security risk & unknown users December 7, 2005, 11:29 am
Admin Password March 9, 2006, 6:15 pm
Lost local admin password October 4, 2005, 8:17 pm
windows xp 64 admin password reset March 28, 2006, 1:07 pm
Changing local admin password on a set of machine in an ad network ? June 6, 2005, 1:28 pm
Built-in domain admin account password will expire January 3, 2007, 3:03 pm
Key Recovery August 26, 2005, 3:52 am
NT4 user account recovery June 3, 2005, 6:29 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap