Re: Password Visibility



It depends...

If an admin can set up a website with basic auth and convince the user to enter their userid/password they can retrieve that password from the vars. If an admin has the ability to sniff traffic in and out of a DC and some LDAP app the user is using is using simple authentication the password will be in clear text on the wire. If the admin has rights to a DC they could dump the hashes for the user database and then run something like l0phtcrack or some rainbow table software against it to crack the passwords, possibly in milliseconds. Also if an admin is bright enough they could install a password filter on a DC and capture the clear text password of every userid that changes the password. There are more vectors but these are the main ones that spring to my head.

You can audit who changes password with normal AD auditing, I suggest reading up on the topic as it isn't something you just want to go slamming into place as there are performance impacts that can occur.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net


DavidW wrote:
This may seem a very odd or simple question but is it possible for network administrators to see user network passwords? If the answer is yes, is there a way of auditing which administrator reset a user's password and when?


Thanks
.



Relevant Pages

  • Re: Domain to Workgroup change local user password lost
    ... XP asked for a userid/password to do this change with ... local admin credentials, you locked your keys in the car. ... I would like to go back to my original domain. ... If you can't contact the original domain controller over the network, ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How can admin not have access to certain shares?
    ... Auditing the data so that you are alerted when someone accesses it is ... If you don't trust the administrator then you're screwed to start with. ... defining and managing a reasonably well tuned and managed network ... all access to these documents in any way for any purpose by our admin. ...
    (microsoft.public.windows.server.security)
  • The error code was: 3221225578
    ... The admin can still log in fine-but the auditing log shows the error ... then re -checked "Password Never Expires" ...
    (microsoft.public.win2000.security)
  • User log
    ... If he's an admin, he can simply turn off or erase any ... logging or auditing you can turn on. ... >Is there any way i can trap anyone, ...
    (microsoft.public.windowsxp.security_admin)