Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - ms exchange server security

 
Thread Tools Search this Thread
Old 06-29-2005, 05:13 PM   #1
Default ms exchange server security


Just wondering how hard it would be to crack an exhange server email account
if I already have the username and only had to crack the password.(?)




BFM
  Reply With Quote
Old 06-29-2005, 06:04 PM   #2
Michael J. Pelletier
 
Posts: n/a
Default Re: ms exchange server security
BFM wrote:

> Just wondering how hard it would be to crack an exhange server email
> account if I already have the username and only had to crack the
> password.(?)


Certainly having the usernames is helpful...

Depends upon a couple of things

1) What is the password policy? How strong is it?
example: Is it required that passwords have uppercase and numbers?
2) How long is the aging policy? 30 days? 60, 90 days? Never?
3) Do I have access from the "outside" World (ie Internet access) in the
case where you allow authenticated email forwarding.

-Michael


Michael J. Pelletier
  Reply With Quote
Old 06-30-2005, 05:59 AM   #3
Winged
 
Posts: n/a
Default Re: ms exchange server security
BFM wrote:
> Just wondering how hard it would be to crack an exhange server email account
> if I already have the username and only had to crack the password.(?)
>
>

If you don't have access to the server system files and a complex
password was used and you have big pipes and only 1 computer you should
be able to crack it in about 100,000 years or so. If the admins put a 3
missed trys on the password before it locks the account, it may take
somewhat longer. If complex password enforcement is not in place and
the administrators are complete idiots and did not set a max number of
tries before it locks the account...it is an indeterminable variable.

Bear in mind trying to brute force the account should ring off alarm
bells everywhere if even minimal security monitors are in place. A
decent network will lock you safely away from the server at the firewall
if you try cracking too hard. If there is any possibility that the
system is at all sensitive and business or governmental in nature, you
should be safely in jail long before you access the account.

There are far better ways to access exchange servers with much higher
probabilities of success.

Winged


Winged
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Small business server 2003 and exchange server HB MCITP 1 04-30-2008 04:51 AM
Computer Security Information and What You Can Do To Keep Your SystemSafe! Ann.Anderson.group.com@gmail.com A+ Certification 0 12-06-2007 01:55 AM
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM
Re: Need Ideas For A New Server, Long Post Gareth Church A+ Certification 2 07-27-2003 12:46 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46