Most password-cracking scenarios focus on attacks that convert a captured hash to its plain-text password equivalent using an offline attack and hash or rainbow table database. Capturing password hashes assumes a lot. In most cases, the attacker must have highly privileged access (admin or root) to get to the hashes; if they do, they can inflict much more other damage. So why just discuss password cracking?
Further, in the Windows world, a remote attacker must have local administrator access on a computer and NetBIOS access, which is often blocked by the perimeter firewall. Despite popular belief, today's Windows logon password hashes cannot be sniffed off the wire. Plus, if an attacker can get the hash, he or she can conduct a "pass-the-hash" attack and not worry about converting it in the first place.
[ Roger shares more advice on managing passwords in these Security Adviser posts: "Password size does matter" | "Getting a grip on better password hashes" | "Ask better password questions" ]
Don't be lulled into a false sense of security, though: A complex, six- to eight-character password may have been sufficient 10 years ago, but it's certainly not today. Most of the Linux/Unix systems I've reviewed do not enable their account lockout policy. In the Windows world, the true administrator account cannot be locked out, and some software programs don't log against the account lockout policy. Many companies are disabling the account lockout policy to prevent automated worms, such as Conficker, from locking out all the user accounts and causing an indirect DoS event.
Moreover, most companies still lack a sufficiently adequate auditing system to alert admins of repeated failed logon attempts -- even if the number exceeds the hundreds of thousands. So a remote attacker can enumerate all of your external access points (Outlook for Web Access, Terminal Server, SharePoint, FTP, SSH, RDP, Telnet, and so on) and guess away against your administrator account until he or she breaks it.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Download a free 30day trial and experience how XenDesktop delivers a pristine, ondemand desktop experience to users on whatever device they choose, while cutting IT complexity and costs.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Sign up to receive InfoWorld Resource Alerts
With the continuous expansion of data capacity, completing the full cycle of a scheduled scan can be a very time consuming process. Find out how to efficiently secure EMC Celerra with centralized virus scanning, virus pattern file updates, event reporting and antivirus configuration.
Download now! »A single virus-infected file in a storage system can be responsible for infecting large amounts of data. This white paper details the architecture and product features of Trend Micro's data storage security solution, ServerProtect, and discusses how it has been designed to protect EMC Celerra file servers with minimal overhead.
Download now! »The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.
Download now! »With the emergence of mixed threat attacks, a failure on a single server can quickly impact the entire network. Learn how a technology that is designed to remove and block infected files on application and file servers prevents the virus from reaching users and keeps your Windows network free from malware.
Download now! »