Re: secure storage in Active Directory

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 05/06/03


Date: Mon, 5 May 2003 23:16:21 -0400


Hi Megan,

All data stored in AD is in the DIT file including the passwords which are stored as hashes. Group policy information
has links and version info in AD and the actual policies are stored in flat files in SYSVOL.

--
Joe Richards
www.joeware.net
--
"megan" <zhongmeiyi@yahoo.com.sg> wrote in message news:57257a88.0305041854.13e0f162@posting.google.com...
> Hi,
>
> I understand that the Active Directory stores user data and passwords.
> How does it store these securely within its internal structure?
> i.e. how are the passwords protected? Through hashing? PKI?
>
> I've read that the Active Directory database is the ntds.dit, but
> I've yet to read anywhere that the passwords are stored there. I've
> also read about the NTLM (mostly for backward compatibility with NT
> systems), they store the password hash (either NTLM hash or NTLMv2 hash).
>
> Thanks in advance for any feedback.
> Megan


Relevant Pages

  • Re: secure storage in Active Directory
    ... Hi Megan, ... All data stored in AD is in the DIT file including the passwords which are stored as hashes. ... I've> also read about the NTLM, they store the password hash. ...
    (microsoft.public.win2000.security)
  • Re: Password hashes
    ... NTLM hash as the key. ... There is however no locally stored NTLMV2 hash of passwords. ... Auditing and reviewing the security logs ... secure their network and data and the documentation to do such at TechNet ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Windows XP / 2K3 Default Users
    ... Cracking the 'passwords' has never been ... The gist of the 'technique' is the "Modifying Windows NT Logon Credential" ... existing windows applications that use the hash currently set to ... and then re-use those hashes to try to get authenticated access to other ...
    (Pen-Test)
  • Re: Pidgin IM Client Password Disclosure Vulnerability.
    ... because we need to be able to generate the hash a given ... Some protocols can ask for different types of hashes at ... passwords stored in it ... lost, you have much bigger problems than lost IM passwords. ...
    (Bugtraq)
  • Re: Decrypt fails
    ... I am creating a MD5 hash data and then using it to derive a key ... (CALG_RC2 encryption algorithm). ... My requirement concerns more with not storing passwords in plain ... > that he provided and compare it to the hash in the database. ...
    (microsoft.public.platformsdk.security)