Where are Windows "Enforce password history" passwords stored?

From: Charles Gillman (charles.gillman_at_gmail.com)
Date: 08/29/05

  • Next message: contact_at_webappsec.org: "WASC-Articles: 'Preventing Log Evasion in IIS'"
    Date: Mon, 29 Aug 2005 11:13:43 +1000
    To: pen-test@securityfocus.com
    
    

    Can anyone tell me where the "remembered" passwords are stored when
    the "Enforce password history" is set in Group Policy?

    If this setting is set to its maximum value of 24 then I would expect
    24 password hashes are stored for each account for the setting to
    work. But where?

    More importantly are there any tools/techniques for accessing the
    "remembered" passwords?

    Thanks
    CG


  • Next message: contact_at_webappsec.org: "WASC-Articles: 'Preventing Log Evasion in IIS'"

    Relevant Pages

    • RE: Automatically locking workstations
      ... AD Group policy allows you to force a logout after x amount of time, ... you can enforce a screensaver, with passwords if you choose, or the ... Subject: Automatically locking workstations ... preset timed amount of inactivity? ...
      (Security-Basics)
    • Re: Passwords Expire Too Fast
      ... I'd suggest to download the Group Policy Management Console, ... This will run through all the group policies and show you the ... Exchange/OWA, so if passwords are expiring every 40 days, it must be defined ...
      (microsoft.public.exchange.admin)
    • Re: Setting local admin passwords
      ... A script used outside of group policy is your main ... We need to change these passwords regularly and I am hoping ... there is a group policy of some type that can help control these. ...
      (microsoft.public.windows.group_policy)
    • Re: GPOs dont work at all
      ... After removing the combinations with blank passwords - GP was applied ... run the Group Policy results wizard - this should at least let you see ... Check your group policy refresh interval for both server & clients - make ...
      (microsoft.public.windows.server.sbs)
    • Re: Preventing an account from having a blank password.
      ... Use the Group Policy Editor to block the nusrmgr.cpl applet. ... MS-MVP Windows Media Center\Windows Powered Smart Display\Security ... > the Users& Passwords tool from the control panel, it will allow an account to ... > disable the Users & Passwords icon in the control panel or to force the Users ...
      (microsoft.public.windowsxp.security_admin)