Click
HERE to go directly to our current schedule of
classes
07/16/2008
Administrator Password Tips
I just finished my CCSP certification ... trying to get the Certified
Ethical Hacker Certification... that will really
get me established in the Network Security field. My goal is
to...get a job in the Tokyo Financial district maybe in one of the
investment banks to protect and secure their networks...thanks for all the
help and guidance you have given me throughout my career...
click
here for more testimonials... |
![]() |
|
Weekly Blog - What's Happening Now? Master Class Schedule Daytime Classes Corporate classes Classroom rental meeting rooms Classroom photo albums Pre-registration instructions for corporate IT training classes Microsoft Certifications Windows 2008 Training and Free Server A+ Network+ Security+ Fiber Optics & Cat-5 Computer Security DoD Inst 8570.01-M Mandate Project Mgmt & PMP About HyperLearning Driving, Dining, and Hotel information Contact Us Site Map Price List Bad weather closings? Job opportunities for trainers Job opportunities for students and graduates On-line registration form
|
Administrator Password Security Tips - from a Master Hacker.NOTE: The author of most of these comments is a computer security professional, who has asked that personal identity not be disclosed. This author is currently employed, full-time, in a position that requires travel around the globe regularly, to different locations to attempt to "hack" the computer security. (The author also wears a white hat - so don't be afraid to follow this tip.) I have some concerns with the password tips given on the site below ( http://go.techtarget.com/r/1981127/281587 ). The very first tool that is recommended in that article is PSPasswd, which can be used along with a batch file to automatically change the local administrator password on local and remote machines. The local administrator password should NEVER be the same as the domain administrator password! Second, the local administrator password on one machine should not be the same as the password on another. If this is too much of a management burden, at least ensure that local admin passwords on domain controllers differ significantly. Ideally, the passwords should all be different. Log them in a
binder, and put the binder in a fire-proof safe. Minimize employee
access to the safe/vault. [Only use the local administrator
password, when it is absolutely necessary. In a domain, your
domain login will normally be all you will need to administer a
machine.] There is a way to use this CD in such a manner that allows local
administrator log-in without a password, while at the same time leaving
the original password intact. No, I am not kidding; and no, I will not
tell anyone how. Surprisingly, I can often spread to the domain controllers in this
manner, even if the domain admin password is different. Once I can load
my own software on your network, it is not your network anymore!! You should enable NTLM, DISABLE LM, and require a minimum password length of 15 characters. [Note: Active Directory wil not allow you to set minimum password length to 15 characters, so set Active Directory minimum password policy to 14 characters, and make 15 characters a written policy.] Complexity does not matter as far as cracking is concerned. [In fact
a "Complex passwords" policy, as it is currently known in the
computer-world is counter-productive. It just makes passwords
harder to remember. Teach people to create long, easy to remember
(for them) "Pass-phrases." A good example might be "Password is
not enough!" This far-exceeds the required 14 characters, is complex
(upper and lower case characters, special characters, and spaces), and
easy to remember. With pass-phrases implemented, you can even
relax the requirement to change passwords to once a quarter or twice a
year.] With a long password or pass-phrase, even shoulder-surfing
becomes difficult. Trust me. ;) |
|
We are an OppInc/Workforce Investment Act (
http://nex-step.org/job_seekers/workforce_centers.htm ) Approved Contractor;
we participate with Tidewater Community College's (TCC) Virginia
Workforce Development program (
http://www.tcc.edu/wd/ ); and we are
approved for GI Bill computer certification.
We can even refer you to a bank (if your credit is good, or you have a
co-signer) HyperLearning Technologies
|
[Projected Certification Training Night Class Schedule ] [ Technology Certification Certification Training Capabilities at HyperLearning Technologies in Virginia Beach ] [ Microsoft MSCE MCSA MCP MCDST MOUS / MOS Certification Training ] [ Data Cabling Fiber Optic Training and Certification ] [ Computer Security Training and Certification ] [ PMP Project Management Professional PMI Credential ] [ About HyperLearning Technology Certification Training ] [ Facility Description Nine and Twelve Student Hands-on Classrooms ] [ What Customers are Saying ] [ Web-based eMail Contact Form ] |
CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, Cisco IOS, Cisco Systems, the Cisco Systems logo, and Networking Academy are registered trademarks or trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries. MCSE, MCSA, MCP, MCDBA, MCDST, MOUS / MOS, Windows Server 2003, Small Business Server 2003, SBS 2003, Microsoft Exchange, Microsoft ISA server, Microsoft Official Curriculum, MOC, Windows XP, Microsoft Certified Trainer, MCT Microsoft Certified Business Partner and other Microsoft related logos are registered trademarks of Microsoft Corporation. A+, Network+, N+, Security+, S+, Linux+, Server+, Certified Technical Trainer, CTT+ and CompTIA logos are registered trademarks of CompTIA. Transcender Practice Certification Tests and Transcender partner logos are registered trademarks of Transcender Corporation. VUE / Prometric certification test numbers and the VUE /Prometric logos are registered trademarks. All other trademarks mentioned in this document or Web Site are the property of their respective owners.
![]()
Hyperlearning Technologies is Certified to operate in Virginia by the State Council of Higher Education of Virginia. VA or the "GI Bill" (Veterans Education Benefits) is available for all the computer training programs we offer. Hyperlearning Technologies is also an approved training contractor for the Virginia Workforce Redevelopment financial assistance program. Providing computer training and certification training for all of Hampton Roads Virginia, from the Peninsula to Southside, including Newport News VA, Hampton, VA, Yorktown. Phoebus, Portsmouth VA, Suffolk VA Chesapeake VA, Norfolk VA, and Virginia Beach.
Webmaster Will Harper, MCSE, MCT, CCNA 07/16/2008 09:53
(Other sites maintained by webmaster, http://www.twosteptidewatere.com http://www.parkwaymfg.com http://www.gtechnetworks.com http://www.willharper.com )