Windows 2000 password policy bypass possibility

From: Leonid Mamtchenkov (leonidat_private)
Date: Wed Mar 06 2002 - 23:40:51 PST

  • Next message: Mandrake Linux Security Team: "MDKSA-2002:020 - mod_ssl update"

    Hello All,
    
    I have noticed the following behavior with Windows 2000 and I am not
    yet sure whether that is a bug or a feature.
    
    It is possible to create a security policy regarding passwords for
    Windows 2000, that will require users to use secure passwords, which
    should be periodically changed.  It is also possible to make Windows
    remember several previous passwords (18 in our case).
    
    Now, when time comes for user to change the password, system checks
    whether or not new password is among those 18 old ones.  If it is not,
    and password satisfies other conditions, then password changes.
    
    It is possible for user though to change the password without waiting
    for it to expire.  When changing this password, password history check
    is not done, but check for all other conditions is performed.
    
    Is this issue serious enough to be forwarded to Microsoft, or is it
    supposed to work this way?
    
    -- 
    Best regards,
      Leonid Mamtchenkov, RHCE
      System Administrator
      Francoudi & Stephanou Ltd.
    



    This archive was generated by hypermail 2b30 : Fri Mar 08 2002 - 17:26:16 PST