Penetration Testing mailing list archives

Re: Password storage - Reversible encryption in AD.


From: mathieu.diepman () getronics com
Date: 11 Jan 2006 12:13:15 -0000

Hi Doug,

I was wondering if you've been able to retrieve the password from AD when reversible encryption is enabled. 

Everyone seems to agree that it's a dangerous setting to enable, but no-one can tell me how to get the actual password 
for my temporary workaround...

thanks!
Mathieu

------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 

Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:

http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


Current thread: