755 : User Account Policy Password Never Changed/Expires
Printer | http://osvdb.org/755 | Email This | Edit Vulnerability

Views This Week

5

Views All Time

102

Info

Last Modified

4 months ago

Percent Complete

90%

Disclosure

Unknown

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Some systems are configured so that user accounts have passwords that do not expire. This means a user can continue logging into the account with the same password indefinitely. This is considered by most to be a bad security practice as it may assist an attacker carry out brute force style attacks against the system, with a higher chance for success. In addition, if an attacker is able to get a password via a method such as 'trashing' or obtaining the hashed passwords, by the time they are able to try to login with it, the password may be changed. By requiring users to change their passwords frequently, it is more difficult for an attacker to carry out such attacks and significantly lowers the window of risk.

Classification

Location: Local Access Required, Remote/Network Access Required
Attack Type: Authentication Management
Impact: Loss of Confidentiality, Loss of Integrity
Exploit: Exploit Available
Disclosure: OSVDB Verified
OSVDB: Best Practice

Solution

Administrators should maintain a strong password policy which includes forcing users to change their passwords every 30 to 90 days. This should apply to any account that has significant user privileges or access to sensitive information.

Products

All Vendors
Watch-list
All Products
Watch-list
All Versions

References

Tools & Filters

Nessus

10914 10916

Credit

Unknown or Incomplete

Blogs

None found at this time

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use