Solved

Why did this sysadmin use Reversible Encryption?

Posted on 2009-07-14
6
237 Views
Last Modified: 2013-12-04
I've just taken over support on a small Windows server from a prior sysadmin who the Director no longer trusted.  I've looked at the network setup, and notice that the Director's User account is the ONLY account on the network set with "Reversible Encryption".   She does nothing beyond ordinary Office applications, and sometimes uses Remote Web Workspace to connect from home.

Why might he have set this, and what might he have been up to?  If he was snooping, he would have wanted to do it from home, but I'm not sure what benefit there would have been to this setting, when he could already remote in with Admin rights.  The only thing he might have wanted to do which isn't as easy just logging in as admin was to follow her email... so perhaps he wanted to log on as her to snoop that way?  if so, could this have helped?

He was definitely antagonistic towards her - I knew him!


0
Comment
Question by:jennynover
  • 3
  • 2
6 Comments
 
LVL 33

Accepted Solution

by:
Dave Howe earned 120 total points
ID: 24851803
The main use of reversible encryption is to decrypt the password of a user who frequently forgets it - however, it is more likely that in this case the former admin was interested in the password not to log into that system (which could be done easily) but for either or both of

1) access to EFS encrypted files that lack a recovery agent

2) access to other systems (like webmail) as most users use the same password for all their systems.

given he could just have set a recovery agent though, its much more likely to be the latter.
0
 
LVL 4

Author Comment

by:jennynover
ID: 24852733
Thanks. ... and how do you decrypt the password?
0
 
LVL 4

Author Comment

by:jennynover
ID: 24853176
... and is there anything else I should be looking out for to lock down the server (extra points!).  I've closed all ports at the router, except those needed for RWW...   Or any other security holes he might have left I should look out for on the server (I notice that he downloaded TSWeb and saw logon type 8 records from before he left - which may be related).
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 19

Expert Comment

by:CoccoBill
ID: 24859632
0
 
LVL 33

Expert Comment

by:Dave Howe
ID: 24861253
I think the "cain" tool from cain and able can do it - admittedly though, I have never tried.
0
 
LVL 4

Author Comment

by:jennynover
ID: 24862794
Thanks Cocobill also for the links, not specific to the Q; but useful information.  Will go through.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Recently, I read that Microsoft has analysed statistics for their security intelligence report. It revealed: still, the clear majority of windows users do their daily work as administrator. An administrative account is a burden, security-wise. My ar…
Read about achieving the basic levels of HRIS security in the workplace.
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

896 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now