Jump to content

Recommended Posts

Posted (edited)
A great example of this is ADMT. ADMT has a password extractor service that runs on a DC and extracts the password so it can be synced to another domain. I'm going through 4 domain mergers at the moment and it is quite scary how insecure it can be. Anyway back on topic.

 

Does any one have any other suggestions, ideas or opinions except for the password portal viewer.

 

While I know you want to bypass this issue now, I think you've misunderstood how they systems work.

 

ADMT uses a 16~ length character hash of a password to sync over (Combined with the encryption key imported at the destination), and at no time provides clear-text passwords to the users or system.

 

There is never a good reason to be doing what you're asking, give them an option to reset passwords if you want this, but you shouldn't be effectively stealing any passwords they're creating as it might link to other personal accounts to. Even Microsoft says you should never turn on reversible encryption (let alone clear text...) unless there's no other way around getting an old piece of software to work properly.

 

And on subject, I do feel like others mentioned if you're re-doing another intranet etc it would be better to add on or build some of the original projects rather than doing another one, when many people are already using HAP etc there's really no need to re-do it from scratch again. Even if there's elements you don't like etc, or feel could be done better, you can still add modules onto the project so schools who are using it now don't need to chop/change.

 

Steve

Edited by Steve21

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...