 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Indentifying end users with weak passwords</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/</link>
	<description></description>
	<lastBuildDate>Fri, 24 May 2013 17:13:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: timbol</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/#comment-43212</link>
		<dc:creator>timbol</dc:creator>
		<pubDate>Fri, 27 May 2005 10:03:33 +0000</pubDate>
		<guid isPermaLink="false">#comment-43212</guid>
		<description><![CDATA[If you happen to use Retina, to check password strength.  Be aware that if you are not very careful, you will,,, lock out your entire network within minutes.

Big time - D?Oh!
]]></description>
		<content:encoded><![CDATA[<p>If you happen to use Retina, to check password strength.  Be aware that if you are not very careful, you will,,, lock out your entire network within minutes.</p>
<p>Big time &#8211; D?Oh!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: colinnz</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/#comment-43213</link>
		<dc:creator>colinnz</dc:creator>
		<pubDate>Thu, 26 May 2005 07:37:35 +0000</pubDate>
		<guid isPermaLink="false">#comment-43213</guid>
		<description><![CDATA[And there are those users who will glue a postit note to their laptop keyboard with a running list of their current passwords...

Luckily this person(s?) are no longer employed by us - however knowing the above, it kind of raised our eyebrows when the user concerned kicked up a stink regarding unencrypted emails.

Priorities, Priorities, Priorities...]]></description>
		<content:encoded><![CDATA[<p>And there are those users who will glue a postit note to their laptop keyboard with a running list of their current passwords&#8230;</p>
<p>Luckily this person(s?) are no longer employed by us &#8211; however knowing the above, it kind of raised our eyebrows when the user concerned kicked up a stink regarding unencrypted emails.</p>
<p>Priorities, Priorities, Priorities&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: scobb99</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/#comment-43214</link>
		<dc:creator>scobb99</dc:creator>
		<pubDate>Tue, 24 May 2005 11:22:37 +0000</pubDate>
		<guid isPermaLink="false">#comment-43214</guid>
		<description><![CDATA[I would second poppaman&#039;s advice about clearing any password &#039;cracking&#039; with management. Some employees will be offended. One approach is to point out, to management and employees, that the tool you are using is freely available to &#039;bad guys.&#039;

And some employees won&#039;t believe they have weak passwords. This happened to my wife when she ran L0phtCrack in her role as security officer at a secure government facility (i.e. a place where all employees are supposed to understand secrecy). When she emailed employees who had weak passwords, one simply didn&#039;t believe she could have &#039;guessed&#039; his password and came to her office to tell her as much. In order to let him know she knew, without breaking the protocol against revealing passwords, she said &quot;Cock-a-doodle-do!&quot; (yes, his password was rooster). He was stunned.

Discretion being the better part of valor, I would, after getting permission to run a password cracker and finding managers using weak passwords, first use an &#039;all hands&#039; type message about the problem so nobody feels singled out.  That message would let folks know that there would be more checks in the future. If those follow-up checks indicate some folks are not changing their ways, then you will have to decide how to deal with them. This will depend on what authority you have, the organizational culture, etc.

I would also second the advice to stand ready with help for people who have difficulty coming up with strong passwords.

Stephen
]]></description>
		<content:encoded><![CDATA[<p>I would second poppaman&#8217;s advice about clearing any password &#8216;cracking&#8217; with management. Some employees will be offended. One approach is to point out, to management and employees, that the tool you are using is freely available to &#8216;bad guys.&#8217;</p>
<p>And some employees won&#8217;t believe they have weak passwords. This happened to my wife when she ran L0phtCrack in her role as security officer at a secure government facility (i.e. a place where all employees are supposed to understand secrecy). When she emailed employees who had weak passwords, one simply didn&#8217;t believe she could have &#8216;guessed&#8217; his password and came to her office to tell her as much. In order to let him know she knew, without breaking the protocol against revealing passwords, she said &#8220;Cock-a-doodle-do!&#8221; (yes, his password was rooster). He was stunned.</p>
<p>Discretion being the better part of valor, I would, after getting permission to run a password cracker and finding managers using weak passwords, first use an &#8216;all hands&#8217; type message about the problem so nobody feels singled out.  That message would let folks know that there would be more checks in the future. If those follow-up checks indicate some folks are not changing their ways, then you will have to decide how to deal with them. This will depend on what authority you have, the organizational culture, etc.</p>
<p>I would also second the advice to stand ready with help for people who have difficulty coming up with strong passwords.</p>
<p>Stephen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: poppaman</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/#comment-43215</link>
		<dc:creator>poppaman</dc:creator>
		<pubDate>Sun, 08 May 2005 09:12:23 +0000</pubDate>
		<guid isPermaLink="false">#comment-43215</guid>
		<description><![CDATA[All good suggestions (I use MBSA and Shavlik myself) HOWEVER:

If you run L0phtCrack or John the Ripper or any other software, program, routine, script, batchfile, etc... (you get the drift) to crack passwords be sure to get both your manager and your manager&#039;s manager to sign off on the activity prior to running the process.  There&#039;s nothing worse than performing a process in the name of network security and towards the betterment of the organization, and being dismissed for hacking activity...]]></description>
		<content:encoded><![CDATA[<p>All good suggestions (I use MBSA and Shavlik myself) HOWEVER:</p>
<p>If you run L0phtCrack or John the Ripper or any other software, program, routine, script, batchfile, etc&#8230; (you get the drift) to crack passwords be sure to get both your manager and your manager&#8217;s manager to sign off on the activity prior to running the process.  There&#8217;s nothing worse than performing a process in the name of network security and towards the betterment of the organization, and being dismissed for hacking activity&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jameslambert</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/#comment-43216</link>
		<dc:creator>jameslambert</dc:creator>
		<pubDate>Mon, 02 May 2005 13:38:16 +0000</pubDate>
		<guid isPermaLink="false">#comment-43216</guid>
		<description><![CDATA[I agree that MBSA will work and it is free.

If you are looking to buy something then Shavlik has a product - Account Inspector.  We use Shavlik for our patch management and this came with the Pro Suite.]]></description>
		<content:encoded><![CDATA[<p>I agree that MBSA will work and it is free.</p>
<p>If you are looking to buy something then Shavlik has a product &#8211; Account Inspector.  We use Shavlik for our patch management and this came with the Pro Suite.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: spacemonkey</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/#comment-43217</link>
		<dc:creator>spacemonkey</dc:creator>
		<pubDate>Mon, 02 May 2005 07:47:05 +0000</pubDate>
		<guid isPermaLink="false">#comment-43217</guid>
		<description><![CDATA[During your migration you may need to reset the users passwords to make sure there desktops migrated.  On the release day your users will need to change there passwords at this point have your help desk staff ready for calls from users who can not come up with 8 character Alphanumeric passwords.
If you want to be able to see how many users will be affected by this user the MS security Analyzer at http://www.microsoft.com/technet/security/tools/mbsahome.mspx
It is free. But will not show you the passwords.
L0phtcrack and Jack the Ripper will work and will give you any passwords that it cracks.  This could become a policy issue for your company if you cracked the password for the director of HR.

This was a problem for us during our migration.  What we did was explain to our end users what makes a secure pass word and a few examples for day one of our migration.
]]></description>
		<content:encoded><![CDATA[<p>During your migration you may need to reset the users passwords to make sure there desktops migrated.  On the release day your users will need to change there passwords at this point have your help desk staff ready for calls from users who can not come up with 8 character Alphanumeric passwords.<br />
If you want to be able to see how many users will be affected by this user the MS security Analyzer at <a href="http://www.microsoft.com/technet/security/tools/mbsahome.mspx" rel="nofollow">http://www.microsoft.com/technet/security/tools/mbsahome.mspx</a><br />
It is free. But will not show you the passwords.<br />
L0phtcrack and Jack the Ripper will work and will give you any passwords that it cracks.  This could become a policy issue for your company if you cracked the password for the director of HR.</p>
<p>This was a problem for us during our migration.  What we did was explain to our end users what makes a secure pass word and a few examples for day one of our migration.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mnman66</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/indentifying-end-users-with-weak-passwords/#comment-43218</link>
		<dc:creator>mnman66</dc:creator>
		<pubDate>Sun, 01 May 2005 16:15:09 +0000</pubDate>
		<guid isPermaLink="false">#comment-43218</guid>
		<description><![CDATA[There are a couple of different approaches you can take to this:
1. Use the Microsoft Base Security Analyzer. This will find all weak passwords and other security holes associated with your Windows Servers. 
2. Apply a security policy right now for passwords, where you need at least 8 digits and variable other criteria. (You&#039;ll find out quick from who is calling in with questions. Kind of backwards, but you might get by with it.)
3. You can write, or find a VBS script that will capture this.
4. You can set something up on your firewall with the help of your Network Admin, or capture it that way.

Hope this helps.]]></description>
		<content:encoded><![CDATA[<p>There are a couple of different approaches you can take to this:<br />
1. Use the Microsoft Base Security Analyzer. This will find all weak passwords and other security holes associated with your Windows Servers.<br />
2. Apply a security policy right now for passwords, where you need at least 8 digits and variable other criteria. (You&#8217;ll find out quick from who is calling in with questions. Kind of backwards, but you might get by with it.)<br />
3. You can write, or find a VBS script that will capture this.<br />
4. You can set something up on your firewall with the help of your Network Admin, or capture it that way.</p>
<p>Hope this helps.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 3/10 queries in 0.037 seconds using memcached
Object Caching 351/357 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-24 18:08:35 -->