Home > Step 1: Understanding the limitation
Step-by-Step Guide:
EMAIL THIS

Step 1: Understanding the limitation

05 Dec 2005 | SearchWindowsSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

The best way to approach testing for password weaknesses in your organization is from an ethical hacking perspective. The first -- and perhaps most important -- thing this involves is obtaining permission from upper management. If you're a consultant, written sign-off from your clients is especially important. Also, work by the Golden Rule when testing for password weaknesses and respect the privacy of others by protecting and never sharing the information once passwords are uncovered. This is not only the ethical thing to do but it's also a good way to keep from losing your job or getting into legal hot water.

The next step is to determine how you're going to go about your testing. You could test from the outside -- a true hacker's-eye-view -- or as an authenticated user and administration on the internal network. If you want to simplify things and jump right in, you can simply run a password cracking program against your domain controller or specific computer(s) you wish to test. However, that's only half the story since there are likely so many other passwords around. Therefore, I recommend both the external and internal tests.

The external view will show you how things really appear from the outside. In this type of testing you can try to crack the following types of passwords from the outside world:

  • IIS/Web applications
  • SQL Server
  • E-mail (SMTP, POP3, OWA, etc.)
  • Terminal Services
  • Remote Desktop Connections via RDP
  • VNC and other third-party remote access software
The internal views as both a regular user and an administrator are valuable as well. Running such tests as a regular user with minimal network rights shows what the average employee, contractor, and other insider can see on the network. Finally, a follow-up cracking test logged in as an administrator equivalent will find additional weaknesses you may have overlooked or not been able to access otherwise. In this type of testing you can try to crack the passwords mentioned above (since you'll likely have a different network perspective inside the firewall) and, in addition, the following types of passwords as well:
  • Local accounts
  • Domain accounts
  • Service accounts
  • Windows shares
  • NT cached secrets
  • Protected storage (i.e. cached Internet Explorer, Outlook, etc. passwords)
  • PWL files
  • File protection passwords (i.e. protected .doc, .xls, .pdf, .zip, etc. files)
  • Passwords stored in cleartext files on local and network drives
As you can see, there are more than just Windows passwords that can introduce information security risks on your network. Note that some of these tests require you to be logged into the local machine. This is obviously not realistic for more than a dozen or so machines; however, you should run them on your servers and critical workstations at a minimum.


Cracking network passwords

 Home: Introduction
 Step 1: Understanding the limitation
 Step 2: Tools you should use
 Step 3: What good are your findings?

ABOUT THE AUTHOR:
Kevin Beaver is an independent information security consultant, author and speaker with Atlanta-based Principle Logic LLC. He has more than 17 years of experience in IT and specializes in performing information security assessments. Beaver has written five books, including Hacking For Dummies (John Wiley & Sons, Inc.), the brand new Hacking Wireless Networks For Dummies and The Practical Guide to HIPAA Privacy and Security Compliance (Auerbach Publications). He can be reached at kbeaver@principlelogic.com.
Copyright 2005 TechTarget


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
User passwords and network permissions
20 days to a more secure enterprise
Eight is too many characters for strong passwords
Nine common password oversights to avoid
Secure your Windows systems with proper password practices
Managing multiple passwords in Windows
Windows desktop endpoint security challenges podcast series
How to strike a balance between Windows security and business needs
Managing single sign-on security burdens in Windows
Build secure computer password policies
Remote user security checklist

Microsoft Windows XP Pro
Guide to converting from Windows XP to Windows 7
Top 5 registry keys for Windows XP
Manage the desktop image lifecycle to limit work, ensure security
Secure Windows XP before a Windows 7 upgrade
Microsoft's August patches run the gamut
Hold on to Windows XP at your peril
XP stragglers blame hardware costs, new features
Your questions answered: The Windows 7 upgrade quandary
Windows Vista users get little pricing relief on Windows 7
Vista shops eye quick path to Windows 7, XP shops likely to resist

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
key-value pair  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




Windows Admin Solutions - User Management, Application Management, Windows Deployments
HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts