Local Administrator Password Selection
Local passwords are passwords that are stored and authenticated on the local system (e.g., a workstation or server). Although most local passwords can be managed using centralized password management mechanisms, some can only be managed through third-party tools, scripts, or manual means.
A common example is built-in administrator and root accounts. Having a common password shared among all local administrator or root accounts on all machines within a network simplifies system maintenance, but it is a widespread weakness. If a single machine is compromised, an attacker may be able to recover the password and use it to gain access to all other machines that use the shared password.
Organizations should avoid using the same local administrator or root account password across many systems. Also, built-in accounts are often not affected by password policies and filters, so it may be easier to just disable the built-in accounts and use other administrator-level accounts instead.
Computer Security Related Articles
Firewall plannings
Deploy and Manage Firewalls
Firewall Planning in Details
Firewalls Security | Policies Based on Applications
Firewall security and policies | IP Addresses and Characteristics
Architecture with Multiple Layers of Firewalls
Network Layouts with Firewalls
Firewalls security - Dedicated Proxy Servers
Firewalls security - Application Proxy Gateways
Firewalls security| Packet Filtering
ipv6 protocol | Implementation and Deployment
Firewalls and Network Architectures
Distributed Firewalling for more Security
Firewalls Developing and Testing
Firewall - VPN Solutions
Specific security controls to implement include only permitting authorized administrators from authorized hosts to access the data, requiring strong authentication to access the database (for example, multi-factor authentication), storing the passwords in the database in an encrypted form (e.g., cryptographic hash), and requiring administrators to verify the identity of the database server before providing authentication credentials to it.
Another solution to management of local account passwords is to generate passwords based on system characteristics such as machine name or media access control (MAC) address. For example, the local password could be based on a cryptographic hash of the MAC address and a standard password. A machine's MAC address, "00:16:59:7F:2C:4D", could be combined with the password "N1stSPsRul308" to form the string "00:16:59:7F:2C:4D N1stSPsRul308". This string could be hashed using SHA and the first 20 characters of the hash used as the password for the machine.
This would create a pseudo-salt that would prevent many attackers from discovering that there is a shared password. However, if an attacker recovers one local password, the attacker would be able to determine other local passwords relatively easily.
Regardless of the method chosen, a solution should be implemented that prevents the use of shared local account passwords across many systems.
Internet Security Suites
Zonealarm Internet Security Suite 2010
Release Date: 09/13/2009
Amazon Price: $49.49 (as of 12/07/2009) ![]()
List Price: $49.99
Used Price:
Usually ships in 24 hours
CA Internet Security Suite and 2010 3-User
Release Date: 10/13/2009
Amazon Price: $58.19 (as of 12/07/2009) ![]()
List Price: $69.99
Used Price:
Usually ships in 1-2 business days
Zonealarm Internet Security Suite 2010
Release Date: 09/13/2009
Amazon Price: $49.99 (as of 12/07/2009) ![]()
List Price: $49.99
Used Price:
Usually ships in 24 hours
Internet Security Suite Plus 2009
Release Date: 09/19/2008
Amazon Price: $17.51 (as of 12/07/2009) ![]()
List Price: $79.99
Used Price: $1.98
Usually ships in 1-2 business days
Zonealarm Internet Security Suite 2009
Release Date: 08/15/2008
Amazon Price: $40.99 (as of 12/07/2009) ![]()
List Price: $49.99
Used Price: $24.95
Usually ships in 24 hours
Password Replacing
The attacker does not necessarily need to know the original password to accomplish this-for example, the attacker could intercept a user's legitimate attempt to reset a password. This section describes several ways in which attackers can replace passwords to gain access to accounts.
Forgotten Password Recovery and Resets
Examples of verification methods include basic knowledge-based verification (e.g. employee ID number, badge number, date of birth); predetermined challenge response questions set during account creation (e.g., color of first car, favorite pet's name); calling a user back on an office phone; and requiring a face-to-face visit from the user to provide photo identification.
Each verification method has advantages and disadvantages that should be evaluated before use. Privacy concerns should be carefully evaluated; for example, information such as social security numbers and mother's maiden name should not be used for identity verification.
User verification should not include data or question answers that can be easily obtained or guessed by an attacker, such as an employee ID number available from a company directory. For each password recovery or reset mechanism, the thoroughness of the user verification can be tailored to the account's relative security needs-for example, organizations might want to require a rigorous, out-of-band verification method for the highest-security passwords and use less rigorous methods for other cases.
When selecting verification methods, organizations should consider the relative risk of each method as opposed to its cost and convenience. Organizations should also identify and address any requirements to perform password recovery and resets for people who are not physically located in the organization's main facilities, including users who telecommute or are on travel.
The confidentiality of all sensitive information stored and transmitted as part of password recovery and resets should be protected. For example, if predetermined challenge-response questions or password hint questions are used to verify identity, the confidentiality of the answers should be protected at all times, and the confidentiality of the questions should also be protected if the questions are user-generated or otherwise differ among users.
Organizations should also carefully consider using filters to ensure that the answers set by a user to challenge-response questions have reasonable entropy, such as not using the same answer for each question and not using all one-character answers.
Organizations should send reset passwords through cleartext email messages and other unsecured applications only in the lowest-security situations because of the risk of interception by attackers.
Computer Security Books
Computer Security Basics
Amazon Price: $29.69 (as of 12/07/2009) ![]()
List Price: $44.99
Used Price: $17.36
Usually ships in 24 hours
Network Security: Private Communication in a Public World (2nd Edition)
Amazon Price: $50.80 (as of 12/07/2009) ![]()
List Price: $74.99
Used Price: $26.78
Usually ships in 24 hours
Computer Security: Principles and Practice
Amazon Price: $79.72 (as of 12/07/2009) ![]()
List Price: $108.00
Used Price: $58.95
Usually ships in 24 hours
Introduction to Computer Security
Amazon Price: $46.69 (as of 12/07/2009) ![]()
List Price: $74.99
Used Price: $36.00
Usually ships in 24 hours
Corporate Computer and Network Security (2nd Edition)
Amazon Price: $85.33 (as of 12/07/2009) ![]()
List Price: $106.67
Used Price: $70.00
Usually ships in 24 hours
Access to Stored Account Information and Passwords
Password Management
Password management strategies for safer systems: foil hackers. Strengthen and protect your systems' passwords.: An article from: Journal of Accountancy
Release Date: 07/02/2009
Amazon Price: $9.95 (as of 12/07/2009) ![]()
List Price: $9.95
Used Price:
Available for download now
Norton Password Manager 2004 Advanced Edition Password Management Academic PC
Amazon Price: (as of 12/07/2009) ![]()
List Price: $31.95
Used Price:
Internet Password Organizer: Ruby
Amazon Price: $9.95 (as of 12/07/2009) ![]()
List Price: $9.95
Used Price: $12.80
Usually ships in 24 hours
Password Management and Security Insight
Release Date: 05/14/2009
Amazon Price: $0.99 (as of 12/07/2009) ![]()
List Price: $0.99
Used Price:
Usually ships in 24 hours
Social Engineering
Computer Security Cryptography Articles
Development of a Cryptographic Module
Cryptographic Module Guidance
Cryptography - Security Levels
Cryptographic Module Finite State Model
Cryptographic Modules - Design
Configuration Management
Conditional Self-Tests
Pre-Operational Self-Test
SSP Zeroization
SSP Entry and Output
Environmental Failure Testing Procedures
Single-Chip Cryptographic Modules
Multiple-Chip Standalone and Embeded Cryptographic Modules
Cryptographic Module Specification
Software and Services
Operator Authentication & Logical Interfaces
Cryptography - Acronyms
by PentAngeli
My main areas of expertise are automation,computers and renewable energy.... (more)

