Re: No LM Hash - no really
From: Miha Pihler (mihap-news_at_atlantis.si)
Date: 08/22/04
- Next message: Miha Pihler: "Re: logon failure: the user has not been granted the requested...."
- Previous message: pduff: "AUDIT LOGOFF"
- In reply to: Ian Boyd: "Re: No LM Hash - no really"
- Next in thread: Ian Boyd: "Re: No LM Hash - no really"
- Reply: Ian Boyd: "Re: No LM Hash - no really"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Sun, 22 Aug 2004 10:12:27 +0200
Hi Ian,
I have dumped some information on this URL... Can you check this and compare
to your results.
http://freeweb.siol.net/mpihler/hashes.jpg
One way to also test your environment is to create password that is longer
then 14 characters (15 will be fine). In this case password can not be
stored as LM "Hash" due to LM design.
Next thing to check would be did your client get new policy. At what level
did you set it? Domain, OU, ... ?
I have few passwords to reset now :-)
Mike
"Ian Boyd" <admin@SWIFTPA.NET> wrote in message
news:uhOpyr%23hEHA.3548@TK2MSFTNGP09.phx.gbl...
> The machine has been rebooted - several times.
>
> "Ian Boyd" <admin@SWIFTPA.NET> wrote in message
> news:%23gQTDq%23hEHA.3348@TK2MSFTNGP12.phx.gbl...
> > How do you REALLY disable the generation of Lan Manager password hashes.
> >
> > i have set the group policy on the domain controller (Windows 2000), and
> > added to the domain controller's registry the NoLMHash = 1 DWORD.
> >
> > Then i go to a workstation and reset the password of my domain account.
> >
> > i can then go back to the domain controller, dump the AD password
hashes.
> i
> > then crack it and confirm that the LM Hash exists, and contains my new
> > password.
> >
> >
> > So how does one REALLY disable LM Hashes in an Active Directory
> environment?
> >
> >
>
>
- Next message: Miha Pihler: "Re: logon failure: the user has not been granted the requested...."
- Previous message: pduff: "AUDIT LOGOFF"
- In reply to: Ian Boyd: "Re: No LM Hash - no really"
- Next in thread: Ian Boyd: "Re: No LM Hash - no really"
- Reply: Ian Boyd: "Re: No LM Hash - no really"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|