Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
?
Solved

Disabling users from using dicitonary passwords....enabling complex passwords does not seem to do this

Posted on 2004-08-03
3
Medium Priority
?
223 Views
Last Modified: 2012-05-05
I have a security requirment at work where users are supposed to have a complex passwords containing a minumum of 8 characters, upper and lower case, numbers and/or special characters and CAN NOT be a dictionary word. This is for a stand-alone system and I have enabled Complex Passwords in the local group policy, but that does not seem to do the dictionary check? Any suggestions would be appreciated.
0
Comment
Question by:andy86
3 Comments
 

Expert Comment

by:theravibes
ID: 11712410
In order to answer this question, we need a little more information...

More specifically...

What operating system?
Are the user accounts managed client-side or server-side?
If it is done server-side, is it done by a local profile with server-side authentication, or is it actually a roaming profile?
What operating system is the server running (if it exists)?
What application on the server are you currently using to manage your accounts (Again, assuming that you use server-side authentication)?

If you could answer these quick few questions, then I can help you with the answer.

Perhaps the best solution that you could do if your profiles are managed server-side is to use a blacklisted passwords list, where you would have a large text document containing any strings that you would not like the end user to be capable of using. (I have only seen this ability in linux-based Windows User Profile management applications such as UMS)

You could also be possible to write a script which would check all passwords on the server before acceptance...

Tyson Edwards
0
 

Author Comment

by:andy86
ID: 11721330
to answer your questions. It is several completely stand alone Windows 2000 systems (not connected in anyway). We are using the local security policy(s) in windows. I wish I could network them and run a server, but can not do to government security requirments. I was looking at EnFIlter at http://security.di.unito.it/software/enfilter.html but need to get some more info on it. Have you used any thing like that before? I really wish I could use your suggestion of the linux based wondows profile thing, but am limited in what I am allowed to do.

Let me know what you thnik. Thanks in advance.
0
 
LVL 1

Accepted Solution

by:
CBF-IT earned 200 total points
ID: 11723108
If you are using a win server, I think you will have to find or create a custom password filter. The article at http://www-nt.stanford.edu/docs/leland.html may be of some interest to you in this regard. Dictionary word files are pretty easy to download any where on the internet, so you could use that to get started with your word filter discussed in that article.
0

Featured Post

Threat Trends for MSPs to Watch

See the findings.
Despite its humble beginnings, phishing has come a long way since those first crudely constructed emails. Today, phishing sites can appear and disappear in the length of a coffee break, and it takes more than a little know-how to keep your clients secure.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Considering today’s continual security threats, which affect Information technology networks and systems worldwide, it is very important to practice basic security awareness. A normal system user can secure himself or herself by following these simp…
With more and more companies allowing their employees to work remotely, it begs the question: What are some of the security risks involved with remote employees and what actions should we take to secure them?
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…

580 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question