RE: [despammed] Defeating password cracking

From: Levinson, Karl (LevinsonK@STARS-SMI.com)
Date: 02/19/03

  • Next message: James Kelly: "RE: Windows station permissions, remote control programs, lower priviledge accounts"
    From: "Levinson, Karl" <LevinsonK@STARS-SMI.com>
    To: 'dave' <dave@netmedic.net>, focus-ms@securityfocus.com
    Date: Wed, 19 Feb 2003 15:50:37 -0500
    
    

    Many of your tips do look like they could be effective.

    If you haven't yet, I would want to test any new accounts and passwords that
    you create to confirm whether you can use them in Recovery Console mode or
    Directory Services Restore mode. My guess is if the character doesn't work
    in L0phtcrack or a SAM-cracking utility, they very well might not work in
    these modes... and that could leave you with a irreparable server when a
    server disaster strikes.

    Also, in addition to the problem programs mentioned in the SecurityFocus
    article #10, services like IIS and possibly Exchange may have problems
    running if you use these special characters in the password or account name.
    I will admit to once somehow creating an Exchange 5.5 email account with a \
    backslash in the account name and not being able to delete it from the
    Exchange server. Not such a big problem since you shouldn't be using this
    account for IIS or Exchange, but a potential problem if someone adds these
    characters to other user account names or passwords.

    As you already mentioned, naturally these measures wouldn't prevent someone
    from undoing these changes that you've made by using a remote buffer
    overflow exploit or local privilege escalation or a trojan or cracked
    password from another administrator-equivalent account... or from using a
    boot disk and physical access to the computer to view the files on the hard
    drive.

    Last, since you've pointed out these issues, it could be that the next rev
    of l0phtcrack might deal with some or all of these characters correctly.
    You'd think there would be a way for l0phtcrack to handle these characters
    correctly, since if the SAM process can create the hash correctly, lc should
    be able to as well.

    -----Original Message-----
    From: dave [mailto:dave@netmedic.net]
    Sent: Tuesday, February 18, 2003 2:36 PM
    To: focus-ms@securityfocus.com
    Subject: [despammed] Defeating password cracking

    Simple ways to defeating password recovery boot-disk and password crackers,
    on NT/2000 machines.

    I was bored and trying different characters that L0phtCrack and other
    cracking programs could not detect. While doing so I discovered that by
    using these same characters in user names you could prevent the Boot-disk
    password changers from being able to change the Admin and other passwords.

    [snip]



    Relevant Pages

    • Re: PING: Former AGDers
      ... She has been a pretty decent D2 player and has some ... Remember, if the wife gets addicted, you can register another account ... what would be the ideal characters for me and her to try to ... if you want to discover the teamplay fast, go build a druid, you'll be ...
      (alt.games.warcraft)
    • Re: Account hacked
      ... Two of his most senior characters, a 70 Druid and a 66 Warrior ... most account hacks to my knowledge involved the person ... to steal an ATM by chaining it to the bumper of their truck. ... off...leaving their bumper with the license plate on it chained to the ...
      (alt.games.warcraft)
    • Re: What is the maximal length of usernames on Solaris?
      ... > characters is limiting to some users. ... >> It is quite common for users to want a shorter login ... can't have a name that's already taken, and nobody has to have meetings ... appeared as part of an account name. ...
      (comp.sys.sun.admin)
    • Re: Tough password question!
      ... w2k/wxp/w2k3 support pwds up to 128 characters ... it will not login when the admin ... >>> account and it will login if I change the domain admin password to ... >>> on a normal user account, or even another domain admin. ...
      (microsoft.public.windows.server.active_directory)
    • Re: User Accounts
      ... Change the name of the account. ... hackers as a means of getting a foothold into your system. ... using all upper case or all lower case letters. ... It should contain at least eight characters. ...
      (microsoft.public.windowsxp.help_and_support)