Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Server Security > Login retry delay for administrator

Reply
Thread Tools Display Modes

Login retry delay for administrator

 
 
Tom Sofka
Guest
Posts: n/a

 
      03-26-2010
Account lockout works fine for normal userids but the administrator account
does not lock out. This allows hackers to remotely try dictionary attacks to
login.
My suggestion is to provide a retry delay parameter that kicks in after the
default account lockout limit is reached that is set to something like 1 to
60 seconds (default to 0 for existing behaviour) . It would allow anyone
with a keyboard to keep trying but would render a brute force automated
attack pretty useless since the time would increase dramatically for their
retries. Even better if the ip address captured in the 529 event log could
be the one address the delay is applied to so other automated and valid
logins continue normally. Renaming administrator account is one remedy but
this is suggestion for additional improvement.

----------------
This post is a suggestion for Microsoft, and Microsoft responds to the
suggestions with the most votes. To vote for this suggestion, click the "I
Agree" button in the message pane. If you do not see the button, follow this
link to open the suggestion in the Microsoft Web-based Newsreader and then
click "I Agree" in the message pane.

http://www.microsoft.com/communities...erver.security
 
Reply With Quote
 
 
 
 
Meinolf Weber [MVP-DS]
Guest
Posts: n/a

 
      03-26-2010

Hello Tom,

You shouldn't work with the administrator account nor have it enabled. So
make sure to have more then one full administrator account with long/strong
passwords. Then set also a long strong password for the administrator and
DISABLE it.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Account lockout works fine for normal userids but the administrator
> account does not lock out. This allows hackers to remotely try
> dictionary attacks to login. My suggestion is to provide a retry
> delay parameter that kicks in after the default account lockout limit
> is reached that is set to something like 1 to 60 seconds (default to 0
> for existing behaviour) . It would allow anyone with a keyboard to
> keep trying but would render a brute force automated attack pretty
> useless since the time would increase dramatically for their retries.
> Even better if the ip address captured in the 529 event log could be
> the one address the delay is applied to so other automated and valid
> logins continue normally. Renaming administrator account is one
> remedy but this is suggestion for additional improvement.



 
Reply With Quote
 
Tom Sofka
Guest
Posts: n/a

 
      03-27-2010
I GET IT!!! Now please note this is a suggestion.
Address your reply as to why the suggestion is bad or good.
I am not looking for workarounds. I think this is something that should be
done anyway.

"Meinolf Weber [MVP-DS]" wrote:

> Hello Tom,
>
> You shouldn't work with the administrator account nor have it enabled. So
> make sure to have more then one full administrator account with long/strong
> passwords. Then set also a long strong password for the administrator and
> DISABLE it.
>
> Best regards
>
> Meinolf Weber
> Disclaimer: This posting is provided "AS IS" with no warranties, and confers
> no rights.
> ** Please do NOT email, only reply to Newsgroups
> ** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
>
>
> > Account lockout works fine for normal userids but the administrator
> > account does not lock out. This allows hackers to remotely try
> > dictionary attacks to login. My suggestion is to provide a retry
> > delay parameter that kicks in after the default account lockout limit
> > is reached that is set to something like 1 to 60 seconds (default to 0
> > for existing behaviour) . It would allow anyone with a keyboard to
> > keep trying but would render a brute force automated attack pretty
> > useless since the time would increase dramatically for their retries.
> > Even better if the ip address captured in the 529 event log could be
> > the one address the delay is applied to so other automated and valid
> > logins continue normally. Renaming administrator account is one
> > remedy but this is suggestion for additional improvement.

>
>
> .
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IE 8 Download From FTP Site Without Login WCarp Internet Explorer 1 02-17-2010 02:36 PM
Long delay to login gerald B. Windows Small Business Server 10 11-14-2009 12:46 AM
XPOST: Fast boot, delay after 1st login if privileged action required Linus Schroeder Windows Vista Installation 2 12-20-2008 12:38 PM
Delay After Login Mike Windows Vista Performance 0 06-02-2007 01:10 AM
Fast boot, delay after 1st login if privileged action required Linus Schroeder Windows Vista Performance 0 02-23-2007 04:33 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59