PASSWORD SECURITY ON DOMAIN CONTROLLER (PWDUMP)

J

jabottt

Hi
I 'm trying to find out if it's possible to do the following on our
network:

1. Access a user's desktop by logging in as that user.

In order to do this, we need to know if we need to go to the domain
controller to extract the user's password hash.

We read somewhere that a salted version of the password is kept in a
password history cache on the desktop. Is this true? Does this mean
that the user's account can be compromised without touching the Domain
Controller?
Thanks
Jon
 
J

jabottt

thanks for the answer Andrei. Well then, I guess that it's almost
impossible to extract a user's password from a desktop on a network?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top