Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Where are Windows "Enforce password history" passwords stored? |
|---|---|
| Date: | Wed, 31 Aug 2005 07:21:55 -0400 |
I agree...having access to pas passwords is a big gain. Consider the following, an employee uses the following password scheme, Password1, Password2, Password3, Password4 and the current password is Password5. I'll bet you I know what the next password will be. - Nick -----Original Message----- From: Wil.Allsopp@ins.com [mailto:Wil.Allsopp@ins.com] Sent: Tuesday, August 30, 2005 4:59 PM To: pen-test@securityfocus.com Subject: RE: Where are Windows "Enforce password history" passwords stored? James Leighe [jamesleighe@gmail.com] wrote:
It's stored as a hash, so if you find out how to access them, you would have to crack it. So basically, it's not worth the time when an attacker could just go for the current password.
This shows a fundamental misunderstanding of security as well as the way hackers think. There are many advantages for an attacker to have your previous passwords - passwords are reused and some may be current on peripheral or entirely separate systems. Wil
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: Business justification for pentesting, Irene Abezgauz |
|---|---|
| Next by Date: | Re: Business justification for pentesting, Jan van Rensburg |
| Previous by Thread: | Re: Where are Windows "Enforce password history" passwords stored?, totiebash |
| Next by Thread: | WASC-Articles: 'Preventing Log Evasion in IIS', contact |
| Indexes: | [Date] [Thread] [Top] [All Lists] |