Jump to content

Recommended Posts

Posted

Found a security problem

When you get your password is going to expire warning and you choose to change it when you get the change password box you can enter another users user name and their existing password and change it.

How can this be stopped?


Posted

The best way to stop it would ensure your password isnt known by others. In order for that to work you have to type in your current password and then your new password. If you dont know the users password you cant change it.

Posted

My domain has the domain name blacked out is there a function to black out the user name or make sure that the box is empty?

Posted
you can enter another users user name and their existing password and change it.

How can this be stopped?

Well, the user shouldn't know another users name and password??

Posted (edited)

Agreed..."blacking out" the user name wouldn't do any good. If you know the password already there's nothing stopping you from logging in as that user and changing the password. Sharing passwords is one of the biggest security problems there is...it's a matter of educating your users not to do this.

Edited by nmX.Memnoch
Posted
Agreed..."blacking out" the user name wouldn't do any good. If you know the password already there's nothing stopping you from logging in as that user and changing the password. Sharing passwords is one of the biggest security problems there is...it's a matter of educating your users not to do this.

The user cant change their password in windows that is not an option on the control alt delete menu.

But they can sure make life harder for the admins just thought there might be a method to blocking it out to make it harder for the end user to change their password

Posted

I'm having a hard time understanding why you would want to keep them from changing their password. Most places require that passwords be changed on a schedule (usually at most every 90 days). It's good security practice to change them as often as possible without it being annoying.

Posted (edited)

Ok,

I am in a domain at work

I get a warning every month ish telling me my password will expire

When i click yes to change the password i get a windows default change password screen i can take out my user name of the user name box and put another users in and change theirs

I am going to tell the admin but i need to know if there is a way to black out the user name box or stop it being edited so i can help my administrator

Hope thats a bit clearer

I don't want the user to not be able to change their password just stop them changing other users passwords

Edited by Mini123
Posted

I don't this is a student environment so people are going to try and get on other user accounts to delete files to get back at other people

I don't know any passwords

Posted

You're misunderstanding how the Change Password screen works.

You have to know the current password before you can change it to a new one. So don't worry, you can't just put in a user name and change the password. :)

Posted

I know how the screen works

All i am asking is there a command you can put into the domain security policy to black out the user name box or stop it being edited

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...