Home page logo

pen-test logo Penetration Testing mailing list archives

RE: Where are Windows "Enforce password history" passwords stored?
From: "Steve A" <pen.test.mail () logicallysecure org>
Date: Tue, 30 Aug 2005 22:31:06 +0100


I asked the same question of NT4 a few years ago on the NTBugtraq list. Russ
did a good summary here

Steve Armstrong

Steve @ logicallysecure.org

-----Original Message-----
From: Charles Gillman [mailto:charles.gillman () gmail com] 
Sent: 29 August 2005 02:14
To: pen-test () securityfocus com
Subject: Where are Windows "Enforce password history" passwords stored?

Can anyone tell me where the "remembered" passwords are stored when the
"Enforce password history" is set in Group Policy?

If this setting is set to its maximum value of 24 then I would expect 24
password hashes are stored for each account for the setting to work.  But

More importantly are there any tools/techniques for accessing the
"remembered" passwords?


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]