Re: ms exchange security

From: Michael J. Pelletier (mjpelletier_at_mjpelletier.com)
Date: 06/29/05


Date: Wed, 29 Jun 2005 10:09:38 -0700

BFM wrote:

> How hard is it to crack a mail exchange server account if I already know a
> username on the server?
>
> The reason I'm asking is a company I know of posts both their exchange
> server IP as well as the format of the username accounts. All a person
> would need to know is a bit about the person or the format of a password -
> and (in my estimation) they could crack an account and have access to
> email. No??

Sure but most good security people put restrictions on passwords. I.E. no
dictionary words, all passwords must have at least 2 uppercase and 2
numerical elements. Also password aging should be around 30 to 60 days. Now
you can still try brute force guessing but, a good security guy will keep
an eye out on the system logs...

I need to stress good security guy/girl as there are many in the industry
who are not and do not follow the guidelines...

-- Michael



Relevant Pages

  • Re: Server not asking for credentials
    ... security policy with no luck. ... I just can't seem to get this 2003 server to ask for the credentials ... access denied without asking for a username and password to connect. ... Server 2000 and applied SP4 to SQL. ...
    (microsoft.public.windows.server.security)
  • Re: Which hardware upgrades are more important
    ... > I don't pretend to know much about security. ... > To get into a website I need a UserName and Password. ... I suppose the Server and Website are somewhat ...
    (comp.databases.ms-access)
  • RE: Sharepoint Login Issue
    ... Change IE internet security settings to low. ... > SPS and new SPS are on same domain. ... > prompted to enter username and password even though they logged on same ... > server they still get anonymus access even I have removed from the server. ...
    (microsoft.public.sharepoint.portalserver.development)
  • Re: Server not asking for credentials
    ... different password on the Windows 2003 server. ... in the security log of the Windows 2003 server to see if there are type 3 ... > username of the local login was different than the username and password ... the server would ask for credentials. ...
    (microsoft.public.windows.server.security)
  • security-basics Digest of: get.123_145
    ... VPN to ASP a security risk? ... Re: Multiple IPSec tunnels? ... Subject: Security NT Server ... VPN to ASP a security risk? ...
    (Security-Basics)