What are the risks associated with the exposure of machine account passwords
in Active Directory? Passwords are changed for machine accounts regularly,
but they don't really expire and can get rather old. If an attacker has
access to this password, what sort of access would he have to other systems
on the network via Kerberos? i.e., would he be able to forge service tickets
as other users and elevate his access elsewhere? The laxness of policy
surrounding these accounts suggests that this is not a huge risk. Should we
be more concerned with these old passwords?

Otis

Reply via email to