We have seen this issue as well and our customers have asked us many times what the deal is. From what we have gathered here the plugin only looks at the registry or SAM and if it sees that one user out of all of the users has not changed their password it reports them all... Now we could be wrong but we have added this plugin to our "list" of plugins not to run. I have seen this plugin report on most M$ systems that users have not changed their passwords where there was a strong password policy in place. We have also seen the same issue with the "User(s) have never logged in" plugin. If someone has more info that would be great! Maybe there is an issue with the way the plugin is grabbing data. Who knows!! :-) For now we are planning on leaving it out and testing passwords using other methods.

Mike Mentges
Security Engineer/Architect
Global Security Technologies Inc.

"Security is not a solution, it is a way of life." -- Linux Administrators Security Guide





[EMAIL PROTECTED] wrote:

During the course of a vulnerability assessment one of the plug-ins (http://cgi.nessus.org/plugins/dump.php3?id=10898) returned a result indicating that many users had never changed their passwords. The results were the same when scanning both the domain controller and the backup domain controller (both NT 4).

The users swear they have been changing their passwords regularly.

I thought at first that the plug-in might be checking the local accounts, but the results are the same for the PDC and the BDC.

If they are in fact changing their passwords, what could be the cause of this result?

Any help is greatly appreciated.

Randy

________________________________________________________________
The best thing to hit the Internet in years - NetZero HiSpeed!
Surf the Web up to FIVE TIMES FASTER!
Only $14.95/ month -visit www.netzero.com to sign up today!
_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus


_______________________________________________
Nessus mailing list
[EMAIL PROTECTED]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to