Solved

Query for a known Admin password

Posted on 2013-01-30
7
236 Views
Last Modified: 2013-02-02
Does anyone know if there is a way to query machines against a known password? For example lets say I have 10 machines that should all have an admin pass of "password". I'm wondering if there is way to query the machines (preferably WMI) and ask is "password" your password and have the machines return a true or false.

Possible?

I would like to use this to try and create an SCCM collection based on machines that do NOT have the correct password, so that I can update them.

Thanks,
Mike
0
Comment
Question by:PAdocIT
7 Comments
 
LVL 31

Assisted Solution

by:merowinger
merowinger earned 100 total points
ID: 38838464
No the password cannot be queried. This would be a huge security risk.
You could write a script which tries an action on all Clients. E.g. create a textfile on C:\
Your script tries different passwords and so it returns an "access denied" or "success" for each password and you know which password is configured...
0
 
LVL 65

Expert Comment

by:RobSampson
ID: 38839002
You could also just go ahead and set the password for a specific account, whether it was already correct or not...that wouldn't make any difference.

Rob.
0
 
LVL 5

Author Comment

by:PAdocIT
ID: 38839198
@merowinger: That's interesting idea. I will have to look into that.

@Rob: That's pretty much what happens now. I was just looking for a way to have a visual representation of which machines had the correct password and which didn't.

I figured there was really no way to query the password, however there people here way smarter than me so figured I would throw it out there. :)

Thanks for the responses.
0
IT, Stop Being Called Into Every Meeting

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 2

Accepted Solution

by:
tighec earned 300 total points
ID: 38839329
If you have a list of machines in a file called machines.txt, you can use the following:

for /F %a in (machines.txt) do net use \\%a\c$ /u:%a\administrator Password || @Echo %a>>BadPassword

It will try to map to the c$ share of each machine, using the administrator account for that machine and the password 'Password'.  If it fails, it will echo out the machine name to txt file 'BadPassword.txt'
0
 
LVL 65

Assisted Solution

by:RobSampson
RobSampson earned 100 total points
ID: 38842295
So why was the question re-opened?  Did you want to regrade it?  If you're going to use tightec's solution, I'd probably add a bit to remove the mapping as well.

Rob.
0
 
LVL 5

Author Closing Comment

by:PAdocIT
ID: 38846002
Thanks guys. Sorry for the regrade, but I thought it fair to give this one to tighec.

@rob: Appreciate the tip. I will definitely add that in.

Thanks again!
0

Featured Post

Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

Join & Write a Comment

This script will sweep a range of IP addresses (class c only, 255.255.255.0) and report to a log the version of office installed. What it does: 1.)      Creates log file in the directory the script is run from (if it doesn't already exist) 2.)      Sweep…
OfficeMate Freezes on login or does not load after login credentials are input.
In this video, we discuss why the need for additional vertical screen space has become more important in recent years, namely, due to the transition in the marketplace of 4x3 computer screens to 16x9 and 16x10 screens (so-called widescreen format). …
This Micro Tutorial will teach you how to the overview of Microsoft Security Essentials. This is a free anti-virus software that guards your PC against viruses, spyware, worms, and other malicious software. This will be demonstrated using Windows…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now