cookie_monster Posted May 20, 2008 Posted May 20, 2008 Who here has the "Do not store LAN Manager hash value on next password change" group policy set at the domain level to prevent LAN Manager password hashs?
joe90bass Posted May 20, 2008 Posted May 20, 2008 (edited) I think I have, I know I was going to do it a while ago............. edit: I lied, I never got round to it. I still have the notes here though. Out of interest, why are you asking? Edited May 20, 2008 by joe90bass
cookie_monster Posted May 20, 2008 Author Posted May 20, 2008 (edited) Because i'm going to do it as we no longer have any 9x / NT4 boxes. I've done a bit of reading and i can't see any issues but i was hoping someone else might of done it already and might of come accross any potential pitfalls e.g SIMS can't authenticate or something. I'll be testing it soon but as i say it's always handy to throw the question out sooner rather than later ;-) I've been using Ophcrack to test and it picked up a pretty good local admin password in minutes when LM was enabled but with it disabled Ophcrack hasn't managed to find any passwords 'yet!!!' Edited May 21, 2008 by cookie_monster
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now