A
Ari
I like to run a tight ship and have taken some security measures to
help keep my system more secure. One topic I've never seen discussed
before is what measures the OS takes if it detects multiple guesses of
the administrators password via the internet-which is likely an
attempt to gain unauthorized access.
I have renamed the administrators account to an unusual name, so
(presumably) an intruder has to somehow figure out the account name
that has administrative privileges. But, let's say this has been done,
and the intruder begins guessing passwords, hoping I was stupid enough
to use a blank line or an easy to guess password (such as
'administrator'::>).
What is to stop the intruder from running all the possible
combinations of passwords until the system unlocks for him (or her).
Clearly, such an attack should (at the very minimum) alert the
keyboard operator and should slow down acceptance of guesses to give
the kb operator more time to respond. But, stopping the computer from
operating if this is detected amounts to an easy means of launching a
denial of service attack....so, clearly shutting down the computer is
not an option.
Just exactly what does XP do when it detects multiple wrong guesses of
the administrators password? Is this issue someting I don't need to
worry about (because XP has it covered), or does XP sit there and
watch it happen?
Thanks,
Ari
help keep my system more secure. One topic I've never seen discussed
before is what measures the OS takes if it detects multiple guesses of
the administrators password via the internet-which is likely an
attempt to gain unauthorized access.
I have renamed the administrators account to an unusual name, so
(presumably) an intruder has to somehow figure out the account name
that has administrative privileges. But, let's say this has been done,
and the intruder begins guessing passwords, hoping I was stupid enough
to use a blank line or an easy to guess password (such as
'administrator'::>).
What is to stop the intruder from running all the possible
combinations of passwords until the system unlocks for him (or her).
Clearly, such an attack should (at the very minimum) alert the
keyboard operator and should slow down acceptance of guesses to give
the kb operator more time to respond. But, stopping the computer from
operating if this is detected amounts to an easy means of launching a
denial of service attack....so, clearly shutting down the computer is
not an option.
Just exactly what does XP do when it detects multiple wrong guesses of
the administrators password? Is this issue someting I don't need to
worry about (because XP has it covered), or does XP sit there and
watch it happen?
Thanks,
Ari