MS Enterprise Password Policy Insecurity
This is 50 minutes of time well spent if you are into security at all, or even more importantly, a windows systems / AD Admin. The short version is the NTLM hash is probably not much, if any, more secure then just plaintext.
DerbyCon 3 0 1301 Cracking Corporate Passwords Exploiting Password Policy Weaknesses Minga Rick Redm - YouTube
DerbyCon 3 0 1301 Cracking Corporate Passwords Exploiting Password Policy Weaknesses Minga Rick Redm - YouTube
Comments
-
Shdwmage Member Posts: 374Great article, I did the whole LinkedIn password check and mine was not one of the ones that was leaked.--
“Hey! Listen!” ~ Navi
2013: [x] MCTS 70-680
2014: [x] 22-801 [x] 22-802 [x] CIW Web Foundation Associate
2015 Goals: [] 70-410