No LM Hash - no really

From: Ian Boyd (admin_at_SWIFTPA.NET)
Date: 08/22/04


Date: Sat, 21 Aug 2004 21:51:14 -0400

How do you REALLY disable the generation of Lan Manager password hashes.

i have set the group policy on the domain controller (Windows 2000), and
added to the domain controller's registry the NoLMHash = 1 DWORD.

Then i go to a workstation and reset the password of my domain account.

i can then go back to the domain controller, dump the AD password hashes. i
then crack it and confirm that the LM Hash exists, and contains my new
password.

So how does one REALLY disable LM Hashes in an Active Directory environment?



Relevant Pages

  • Group Policy Error
    ... Windows cannot query for the list of Group Policy objects. ... In there it suggests that SP1 get installed on the server. ... The second domain controller ...
    (microsoft.public.windows.server.active_directory)
  • Re: Huh? "Login failure: the user has not been granted the requested logon type at this compute
    ... I'm a pretty experienced Windows user and programmer, ... the user has not been granted the requested logon type ... on the appropriate OU to see the Group Policy for that OU]. ... > administrators' group to the domain controller. ...
    (microsoft.public.security)
  • Re: Help with GPO problem! PLEASE!!
    ... How do I create a new GPO? ... I am racking my brain on this problem with a Windows 2003 Standard ... >> Configuration information could not be read from the domain controller, ... Failed to open the Group Policy Object. ...
    (microsoft.public.windows.group_policy)
  • Re: AD sites and services
    ... A search for "Active Directory Sites" yeilds the following: ... After an Unsuccessful Domain Controller Demotion" ... http://support.microsoft.com?kbid=220140 "FRS Replication Protocol and Topology ... Windows 2000 Domain Controllers" ...
    (microsoft.public.win2000.active_directory)
  • Re: GPO Password length not working
    ... The errors running RSOP in logging mode on the XP Pro computers could be ... Configure some settings for both user and computer ... You mention that you are using Group Policy filtering by using groups other ... >> domain container and that the default domain controller Group Policy is ...
    (microsoft.public.windows.server.security)