Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Security Basics: RE: Cached Password concern

RE: Cached Password concern

From: sunny budd <sunnybudd_at_hotmail.com>
Date: Tue, 02 Dec 2003 16:43:35 +0000

Hi

At the moment there is no budget in place to look at extra software to
tighten laptop security though this is of interest.

My primary concern is to avoid credentials being extracted rather than to
protect data - I have had a look now at SAMInside and so far have only
managed to extract Hashes for local accounts not for domain accounts which
have cached credentials (am I missing something?)

I can see no good reason why we use our Domain admin account in the
configuration of laptops but without something concrete I will not be able
to convince my department that this habit should be broken.

Thanks,
S

_________________________________________________________________
On the move? Get Hotmail on your mobile phone http://www.msn.co.uk/msnmobile

---------------------------------------------------------------------------
----------------------------------------------------------------------------
Received on Dec 02 2003

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos