Search specialized certification training options on the HLT site [Home] Click for the Site Map HERE, if your browser
is not Java-enabled (the dropdown won't work)

 
WWW HLT Website  

Click HERE to go directly to our current schedule of classes     07/16/2008


Administrator Password Tips
from a Master Hacker -
He is paid to find security vulnerabilities
HyperLearning Certification Training Virginia Beach Norfolk VA Chesapeake VA Navy Bases Tidewater Community College

I just finished my CCSP certification ... trying to get the Certified Ethical Hacker Certification... that will really get me established in the Network Security field. My goal is to...get a job in the Tokyo Financial district maybe in one of the investment banks to protect and secure their networks...thanks for all the help and guidance you have given me throughout my career... click here for more testimonials...
HyperLearning Technologies Micorsoft MCSE MCSA MCP MCDST MOUS MOS SBS certification, Cisco CCNA CCNP Firewall VPN, CompTIA A+ Network+ N+ Security+ S+ CEH SCP Virginia Beach, Norfolk VA Chesapeake, Portsmouth VA

Weekly Blog - What's Happening Now?


New Class Announcements - Schedule Changes
Master Class Schedule
Daytime Classes
Corporate classes
Classroom rental meeting rooms
Classroom photo albums
Pre-registration instructions for corporate IT training classes
Microsoft Certifications
Windows 2008 Training and Free Server
A+ Network+ Security+
Fiber Optics & Cat-5
Computer Security
DoD Inst 8570.01-M Mandate
Project Mgmt & PMP
About HyperLearning
Driving, Dining, and Hotel information
Contact Us
Site Map
Price List
Bad weather closings?
Job opportunities for trainers
Job opportunities for students and graduates
On-line registration form

Administrator Password Security Tips - from a Master Hacker.

NOTE:  The author of most of these comments is a computer security professional, who has asked that personal identity not be disclosed.  This author is currently employed, full-time, in a position that requires travel around the globe regularly, to different locations to attempt to "hack" the computer security.  (The author also wears a white hat - so don't be afraid to follow this tip.)

I have some concerns with the password tips given on the site below ( http://go.techtarget.com/r/1981127/281587 ).

The very first tool that is recommended in that article is PSPasswd, which can be used along with a batch file to automatically change the local administrator password on local and remote machines.

The local administrator password should NEVER be the same as the domain administrator password!

Second, the local administrator password on one machine should not be the same as the password on another.

If this is too much of a management burden, at least ensure that local admin passwords on domain controllers differ significantly.

Ideally, the passwords should all be different. Log them in a binder, and put the binder in a fire-proof safe. Minimize employee access to the safe/vault.  [Only use the local administrator password, when it is absolutely necessary.  In a domain, your domain login will normally be all you will need to administer a machine.]

Why? Because of another tool recommended in the article, that I never leave home without: Peter Nordhal's NT Password Changer boot disk...

There is a way to use this CD in such a manner that allows local administrator log-in without a password, while at the same time leaving the original password intact. No, I am not kidding; and no, I will not tell anyone how.

Once the local admin password for one machine has been dumped and cracked, I can frequently spread to other machines with the same password.

Surprisingly, I can often spread to the domain controllers in this manner, even if the domain admin password is different. Once I can load my own software on your network, it is not your network anymore!!

If Lan Manager (LM) is enabled, and the password is 14 characters or less, I can crack it in a few hours regardless of the complexity.

You should enable NTLM, DISABLE LM, and require a minimum password length of 15 characters. [Note:  Active Directory wil not allow you to set minimum password length to 15 characters, so set Active Directory minimum password policy to 14 characters, and make 15 characters a written policy.] 

Complexity does not matter as far as cracking is concerned. [In fact a "Complex passwords" policy, as it is currently known in the computer-world is counter-productive.  It just makes passwords harder to remember.  Teach people to create long, easy to remember (for them) "Pass-phrases."  A good example might be "Password is not enough!" This far-exceeds the required 14 characters, is complex (upper and lower case characters, special characters, and spaces), and easy to remember.  With pass-phrases implemented, you can even relax the requirement to change passwords to once a quarter or twice a year.] With a long password or pass-phrase, even shoulder-surfing becomes difficult. Trust me. ;)

I can already hear the nay-sayers: "No one can physically get to my boxes!" Trust me, it can be done. If not, what about the angry guy in the next cubicle who is quitting and going to a competitor in three weeks?
 

Click HERE to ask for additional information.  HyperLearning specializes in Microsoft training, computer security training, CompTIA training, ACES Fiber Optic / Cat 5 / Cat-6 installer training. We focus on YOUR CERTIFICATION. Located in Virginia Beach, serving Norfolk VA, Chesapeake VA, Portsmouth VA, and all of the Hampton Roads Virginia areas.
sign up for computer certification training at HyperLearing Technologies in virginia beach chesapeak va or norfolk va serving Naval Air stations Navy bases and Tidewater Community College TCC
Return to top of page continue mcse mcsa computer security sbs certification training search 

We offer many easy ways to pay for your computer training and certification programs, including Visa and MasterCard  Click this icon to obtain a BBB report on our computer training and certification business in Virginia Beach, also serving Norfolk VA, Chesapeake VA, Suffolk VA, Portsmouth VA and all of Tidewater VA and Hampton Roads VA..  computer training from a microsoft gold certified partner for learning solutions CPLS

We are an OppInc/Workforce Investment Act ( http://nex-step.org/job_seekers/workforce_centers.htm ) Approved Contractor; we participate with Tidewater Community College's (TCC) Virginia Workforce Development program ( http://www.tcc.edu/wd/ ); and we are approved for GI Bill computer certification.  We can even refer you to a bank (if your credit is good, or you have a co-signer)
If you have any questions or would like more information about our training or services, email or call or fax George Geyer, Will Harper, Roger W. Geyer, or Mary Russell, our Training Consultant.

HyperLearning Technologies
Microsoft Gold Certified Partner for Learning Solutions (CPLS)
Computer Training, Computer Certifications, Computer Bootcamps, Computer Classroom Rentals, Corporate Training and Corporate Meeting Rooms

google map to this location

PLEASE NOTE:
HyperLearning has moved to a bigger, better training facility on Feb 18, 2008.
Please update your records and visit us soon!
Click HERE to view Photographs
HyperLearning Technologies
3630 S. Plaza Trail, Suite 250
Virginia Beach, VA 23452
Phone:  757.495.0714 (Training Center)
757.495.5487 (Home Office)
757.651.1117 / 377.3165 (Cell)
Call any time between 8:00 AM and 8:30 PM.
After 5:00 PM, call the Training Consultant line, direct, at (757) 287-5674.
(Training Consultant direct line is not open until after 5:00 PM)
Fax: 757.495.3725
email: Please type 'George.Geyer' '@' 'HyperLearn.com' into your email address to email HyperLearning Technologies' President. Providing Microsoft training, CompTIA training, and computer security trainining in Virginia Beach, Norfolk VA, Chesapeake VA, Suffolk VA, Portsmouth, and all of Tidewater and Hampton Roads / Newport News

Home ] Up ]

 

[Projected Certification Training Night Class Schedule ] [ Technology Certification Certification Training Capabilities at HyperLearning Technologies in Virginia Beach ] [ Microsoft MSCE MCSA MCP MCDST MOUS / MOS Certification Training ] [ Data Cabling Fiber Optic Training and Certification ] [ Computer Security Training and Certification ] [ PMP Project Management Professional PMI Credential ] [ About HyperLearning Technology Certification Training ] [ Facility Description Nine and Twelve Student Hands-on Classrooms ] [ What Customers are Saying ] [ Web-based eMail Contact Form ]

 

CCDA, CCDP, CCIE, CCIP, CCNA, CCNP, Cisco, Cisco IOS, Cisco Systems, the Cisco Systems logo, and Networking Academy are registered trademarks or trademarks of Cisco Systems, Inc. and/or its affiliates in the U.S. and certain other countries.  MCSE, MCSA, MCP, MCDBA, MCDST, MOUS / MOS, Windows Server 2003, Small Business Server 2003, SBS 2003, Microsoft Exchange, Microsoft ISA server, Microsoft Official Curriculum, MOC, Windows XP, Microsoft Certified Trainer, MCT Microsoft Certified Business Partner and other Microsoft related logos are registered trademarks of Microsoft Corporation. A+, Network+, N+, Security+, S+, Linux+, Server+, Certified Technical Trainer, CTT+ and CompTIA logos are registered trademarks of CompTIA.  Transcender Practice Certification Tests and Transcender partner logos are registered trademarks of Transcender Corporation. VUE / Prometric certification test numbers and the VUE /Prometric logos are registered trademarks.  All other trademarks mentioned in this document or Web Site are the property of their respective owners.

Accessibility

Hyperlearning Technologies is Certified to operate in Virginia by the State Council of Higher Education of Virginia. VA or the "GI Bill" (Veterans Education Benefits) is available for all the computer training programs we offer. Hyperlearning Technologies is also an approved training contractor for the Virginia Workforce Redevelopment financial assistance program.  Providing computer training and certification training for all of Hampton Roads Virginia, from the Peninsula to Southside, including Newport News VA, Hampton, VA, Yorktown. Phoebus, Portsmouth VA, Suffolk VA Chesapeake VA, Norfolk VA, and Virginia Beach.

Webmaster Will Harper, MCSE, MCT, CCNA 07/16/2008 09:53

(Other sites maintained by webmaster, http://www.twosteptidewatere.com http://www.parkwaymfg.com http://www.gtechnetworks.com http://www.willharper.com )