Re: How to change "Invalid Login Messages"

From: Colin Nash [MVP] (x_at_x)
Date: 04/29/05


Date: Fri, 29 Apr 2005 00:14:27 -0400


"fjalbuena" <fjalbuena@discussions.microsoft.com> wrote in message
news:84EE6E58-0724-497B-94AF-C51FC683A660@microsoft.com...
> Hi,
>
> Can anyone tell me how, if it is possilbe, to change the message displayed
> to the user when he logs in incorrectly? For example, when a user enters
> the wrong password he gets the message: "The Password is Incorrect. Type
> the
> Pas..... ".
> I want to change this message to only display something like "Invalid
> Logon
> Attempt". So that the user, who might be a hacker trying to break into an
> account, will not know if he got only the user-id wrong or the password
> wrong
> or both.
>
> Thanks for any help regarding this. I think its a security issue when the
> operating system gives hints that the username is correct and only the
> password is wrong.
>
> Thanks again.

Hmm on my PC (XP Pro) it gives the exact same error message "The system
could not log you on. Verify that the user name and password are
correct..." for incorrect usernames and incorrect passwords.

Basically the message tells you that you were not authenticated and doesn't
tell you the reason. In other words, it does exactly what you want.

You're using XP Pro? Maybe Home Edition gives more details (emphasis more
on home user ease-of-use than security) but I've never noticed that.

-- 
Colin Nash
Microsoft MVP
Windows Shell/User 


Relevant Pages

  • Re: LDAP Lookup failure
    ... I thought that was incorrect as well, I think this must be incorrect logging ... I have failure auditing on on the DC policy, but no entries appear from the ... > Did you enable failure audits on the DC and check the logs? ...
    (microsoft.public.windows.server.active_directory)
  • Re: DOT4PRINT driver.
    ... Here are the logs provided by usbmonitor when trying to get the status ... It seems that the data exchanged are incorrect. ... Guillaume. ...
    (microsoft.public.development.device.drivers)
  • How to change "Invalid Login Messages"
    ... Can anyone tell me how, if it is possilbe, to change the message displayed ... to the user when he logs in incorrectly? ... the wrong password he gets the message: "The Password is Incorrect. ... operating system gives hints that the username is correct and only the ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Sitemap error "not found"
    ... I have access to logs. ... No 404 errors thrown. ... > (which is rather incorrect). ... > BATE - program for pH calculations ...
    (alt.internet.search-engines)
  • RE: After upgrade from 98 to XP no password works
    ... PC from Windows Me to XP Pro, I got an error of mssign32.dll file, and after ... still tells me the password is incorrect. ... > floppy drive) but when I enter the password for Administrator it tells me it ...
    (microsoft.public.windowsxp.help_and_support)