Looking for relevant Security Whitepapers? Visit the SearchSecurity.com Research Library.
Buddyfarr | Feb 21 2008 11:52PM GMT
I would not wait for the user to change the password. change his password for him and mark it to change when he logs in. I would also do it to the account of the first person too. If this is a domain then check the server security logs. it will show who logged in and when. the user can easily change the registry to show who the last logged in user was.
Labnuke99 | Feb 22 2008 9:13PM GMT
There could also be the possibility of running a script without interactively logging into the computer that could have done the installation using that user’s credentials if they have the rights to perform the installation. Just a thought.