Anonymous Logon can READ S.A.M. in NT4 Server

From: David Hardinge (dhardinge_at_yahoo.com)
Date: 10/15/03


Date: Wed, 15 Oct 2003 13:26:20 -0700

I am tired of unlocking my accounts because a "poker" can
read my user names on my NT4 server and then try to guess
passwords (3 tries=1 hour lock out). They come in with
ANONYMOUS and have read rights to the Security Account
Manager, then take the list and try to guess passwords.
Is there a way to STOP them from seeing my user names so
they can just guess at Administrator or Guest (which do
not exist on my server)?
  Any help would be appreciated here. I hate unlocking
the accounts 3 times a day because of someone trying to
guess passwords from outside the net.

David Hardinge



Relevant Pages

  • Re: password expiration policy for admin and system accounts ?
    ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
    (microsoft.public.security)
  • Re: password expiration policy for admin and system accounts ?
    ... policy that Admins manually reset these important account passwords every ... You can still have the passwords set to never expire, ... > Privileged accounts should be the most, not the least, well guarded. ...
    (microsoft.public.win2000.security)
  • RE: Security Logging - Passwords & Accounts
    ... Security Logging - Passwords & Accounts ... Does anybody know of any way to log changes to user & group accounts and ...
    (RedHat)
  • Antivirus programs for XP - best ones?
    ... DON'T create user accounts during setup as they will become ... Turn of transmission of passwords and user credentials in clear ... Keep your system and ALL installed applications uptodate (Microsoft ...
    (alt.computer.security)
  • Re: Single Sign On
    ... servers) and setups conducive to such automation. ... have an Active Directory env so you can guess where Kerberos and LDAP ... require user accounts. ... bad guy because I gave them all logins and passwords and they don't have ...
    (Ubuntu)