Re: Service Password
From: Augusto Paes de Barros (apbarros_at_gmail.com)
Date: 07/11/05
- Previous message: k levinson: "RE: Service Password"
- In reply to: John Madden: "Service Password"
- Next in thread: Thierry Zoller: "Re: Service Password"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Mon, 11 Jul 2005 14:19:56 -0300 To: focus-ms@securityfocus.com
John
Yes, there is. The passwords for the service accounts are managed by
the LSA. There is a tool called LSADUMP that can retrieve those
passwords if you have admin rights on the box. Cain (oxid.it) can also
get information protected by the LSA.
Personally that's why I use to say that a simple server compromised
can lead the way for the whole net. Mantaining different accounts and
passwords for services that need to exist and run as admin in all
servers is very hard. Best option to choose products that don't
require this.
Regards,
Augusto Paes de Barros
On 7/11/05, John Madden <chiwawa999@yahoo.com> wrote:
> Hi,
>
> I have a few concerns about windows service password.
> Some services our client uses utilized Domain Admin
> accounts.
>
> The servers are Windows 2003.
>
> Is it something similar to "Cache Credentials" ?
>
> Were are they located ?
>
> Thanks
>
>
>
> ____________________________________________________
> Sell on Yahoo! Auctions – no fees. Bid on great items.
> http://auctions.yahoo.com/
>
> ---------------------------------------------------------------------------
> ---------------------------------------------------------------------------
>
>
-- Augusto Paes de Barros, CISSP/ISSAP http://www.paesdebarros.com.br
- Previous message: k levinson: "RE: Service Password"
- In reply to: John Madden: "Service Password"
- Next in thread: Thierry Zoller: "Re: Service Password"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|