Download Security Update 17 User`s Guide for Windows

Transcript
Modules
Password Strength
Inform the account user of the change and how the user can change the
temporary password.
■
Assign a more secure temporary password to the account. Inform the
account user of the change and how the user can change the temporary
password. See “How to secure your passwords” on page 205.
Password = username
This security check reports accounts with matching user names and passwords.
The check is provided for systems with a large number of user accounts. The
security check is not as thorough as Password = any username. However, if the
Password = any username check takes too much time or consumes too much
CPU, you can use the Password = username check on a daily basis and the
Password = any username check on the weekends.
Intruders frequently try a combination of user names and passwords in an
attempt to break in.
The check returns the following messages:
Message name
Title
DISABLED_GUESSPASS
Guessed user password on disabled account
GUESSPASS
Guessed user password
Type
Class
0
C
4
To protect your computers
◆
Do one of the following:
■
Use the Correct feature to disable the reported accounts that are not
needed, then delete them.
■
Use the Correct feature to disable the reported account. Assign a more
secure temporary password to it, then remove the disabled property.
Inform the account user of the change and how the user can change the
temporary password.
Assign a more secure temporary password to the account. Inform the
account user of the change and how the user can change the temporary
password.
See “How to secure your passwords” on page 205.
■
207