Re: Service Password

From: Augusto Paes de Barros (apbarros_at_gmail.com)
Date: 07/11/05

  • Next message: Thierry Zoller: "Re: Service Password"
    Date: Mon, 11 Jul 2005 14:19:56 -0300
    To: focus-ms@securityfocus.com
    
    

    John

    Yes, there is. The passwords for the service accounts are managed by
    the LSA. There is a tool called LSADUMP that can retrieve those
    passwords if you have admin rights on the box. Cain (oxid.it) can also
    get information protected by the LSA.

    Personally that's why I use to say that a simple server compromised
    can lead the way for the whole net. Mantaining different accounts and
    passwords for services that need to exist and run as admin in all
    servers is very hard. Best option to choose products that don't
    require this.

    Regards,

    Augusto Paes de Barros

    On 7/11/05, John Madden <chiwawa999@yahoo.com> wrote:
    > Hi,
    >
    > I have a few concerns about windows service password.
    > Some services our client uses utilized Domain Admin
    > accounts.
    >
    > The servers are Windows 2003.
    >
    > Is it something similar to "Cache Credentials" ?
    >
    > Were are they located ?
    >
    > Thanks
    >
    >
    >
    > ____________________________________________________
    > Sell on Yahoo! Auctions – no fees. Bid on great items.
    > http://auctions.yahoo.com/
    >
    > ---------------------------------------------------------------------------
    > ---------------------------------------------------------------------------
    >
    >

    -- 
    Augusto Paes de Barros, CISSP/ISSAP
    http://www.paesdebarros.com.br
    

  • Next message: Thierry Zoller: "Re: Service Password"

    Relevant Pages

    • Re: password expiration policy for admin and system accounts ?
      ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
      (microsoft.public.security)
    • Re: password expiration policy for admin and system accounts ?
      ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
      (microsoft.public.win2000.security)
    • RE: Security Logging - Passwords & Accounts
      ... Security Logging - Passwords & Accounts ... Does anybody know of any way to log changes to user & group accounts and ...
      (RedHat)
    • Antivirus programs for XP - best ones?
      ... DON'T create user accounts during setup as they will become ... Turn of transmission of passwords and user credentials in clear ... Keep your system and ALL installed applications uptodate (Microsoft ...
      (alt.computer.security)
    • Re: Problem with openssh 3.7.1p2
      ... > my accounts on the servers have no passwords and ... > the accounts are disabled for login with password. ...
      (SSH)