RE: cached passwords

From: Free, Bob (RWF4@pge.com)
Date: 07/25/01


Message-ID: <2DBFCBE6D1DAD11191E300805F577D1202C10D8B@exchange104.comp.pge.com>
From: "Free, Bob" <RWF4@pge.com>
To: "'tbos1@sears.com'" <tbos1@sears.com>, focus-ms@securityfocus.com
Subject: RE: cached passwords
Date: Wed, 25 Jul 2001 14:59:10 -0700

NT will by default cache the last ten logins' credentials. There is a
registry setting to alter this behaviour.

Cached security credentials, including passwords, are stored and encrypted
in the
registry and protected by an access control list (ACL). RAS uses Local
Security
Authority (LSA) Secrets to store the entries. The default ACL values only
allow
administrators and the user associated with the credentials to gain access
to
these registry entries

Bob Free
Sr. Network Specialist
ISTS/ITUSS/DC/System Server Support
PG&E Auburn, Ca

-----Original Message-----
From: tbos1@sears.com [mailto:tbos1@sears.com]
Sent: Wednesday, July 25, 2001 1:47 PM
To: focus-ms@securityfocus.com
Subject: cached passwords

When a users logs into a NT machine, I was under the impression that the
user profile is cached locally. If this is the case, the password must
also be stored locally somewhere besides the SAM database. Can anyone
confirm this and know if there is a way to secure this (providing there is
a way to access the password).



Relevant Pages

  • RE: SidHistory and password migration with ADMT
    ... SidHistory and password migration with ADMT ... |- added to registry ... |passwords are blanks. ...
    (microsoft.public.windows.server.migration)
  • Re: Securing my app with serial number
    ... The app has two passwords hard-coded into it, we'll call them A and B. ... It then encrypts that string with password A, ... and stores it in the registry as a challenge code. ... I can also insert some extra data into the beginning of unlock code ...
    (microsoft.public.dotnet.languages.vb)
  • RE: SidHistory and password migration with ADMT
    ... In target domain there are deafult user rights in registry ... Should I add some user rights somewhere in source domain? ... SidHistory and password migration with ADMT ... >|passwords are blanks. ...
    (microsoft.public.windows.server.migration)
  • Re: Decode Outlook2003 POP3 password?
    ... >> to decode the Outlook2003 passwords stored in the registry. ... > a second computer connected to the LAN as a bogus POP server. ... > article shows you how to recover Outlook passwords using only the ... > Windows optionally stores Outlook POP passwords in the registry. ...
    (alt.2600)
  • Re: Directory sharing;
    ... You can't preset user names and passwords for NTLM in the registry. ... could build a suitable program that will run on the first boot of the ... My customer wants to connect a desktop machine to a wince device using ...
    (microsoft.public.windowsce.platbuilder)