<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-21992565.post6586919536619604025..comments</id><updated>2010-10-20T12:03:31.069+02:00</updated><category term='it-experts.dk'/><category term='block'/><category term='public beta'/><category term='group policies'/><category term='SQL'/><category term='regional options'/><category term='Outlook'/><category term='Patching'/><category term='SQL Injection'/><category term='registry'/><category term='mdop'/><category term='Security Guide'/><category term='Windows Server 2008'/><category term='software restriction policies'/><category term='updates'/><category term='whitepaper'/><category term='generalize'/><category term='dop'/><category term='terminal services'/><category term='group policy preferences'/><category term='online scanner'/><category term='encryption'/><category term='MSDN'/><category term='admx'/><category term='group policy'/><category term='softgrid'/><category term='windows xp'/><category term='webcast'/><category term='RSAT'/><category term='rdp'/><category term='language pack'/><category term='WMI Filters'/><category term='Mac'/><category term='runas'/><category term='Longhorn'/><category term='technet magazine'/><category term='mlgpo'/><category term='security id'/><category term='mstsc'/><category term='GPDBPA'/><category term='Shared Computer Toolkit'/><category term='xp'/><category term='x64'/><category term='gpo'/><category term='backup'/><category term='adml'/><category term='scripting'/><category term='Shadow Groups'/><category term='orlando'/><category term='windows server 2003'/><category term='Windows Vista'/><category term='specops'/><category term='Security Descriptors'/><category term='sysvol'/><category term='srp'/><category term='webinar'/><category term='security'/><category term='guid'/><category term='Microsoft Application Virtualization'/><category term='Activation'/><category term='MVP'/><category term='policy'/><category term='language'/><category term='best practice analyzer'/><category term='anti-malware'/><category term='wsus'/><category term='gui'/><category term='TechEd'/><category term='service pack'/><category term='hacker'/><category term='beta'/><category term='VBA'/><category term='Jeremy Moskowitz'/><category term='SteadyState'/><category term='UAC'/><category term='software'/><category term='BPA'/><category term='remote desktop'/><category term='network'/><category term='release'/><category term='Darren Mar-Elia'/><category term='exploit'/><category term='anti-virus'/><category term='vista'/><category term='agpm'/><category term='Core'/><category term='Unix'/><category term='display language'/><category term='virtualization'/><category term='starter gpo'/><category term='cab'/><category term='language interface packs'/><category term='public'/><category term='mav'/><category term='kb'/><category term='group policy extensions'/><category term='Powershell'/><category term='connection'/><category term='64bit'/><category term='PolicyMaker'/><category term='OU Filtering'/><category term='hacking'/><category term='endpointsecurity'/><category term='template'/><category term='Oracle'/><category term='mmc'/><category term='The onion ring'/><category term='mui'/><category term='CEH'/><category term='gpanswers.com'/><category term='gp preferences'/><category term='windowsecurity.com'/><category term='download'/><category term='Tor'/><category term='technet'/><category term='ISA'/><category term='online scanners'/><category term='script'/><category term='posters'/><category term='windows'/><category term='newsid'/><category term='starter gpos'/><category term='central store'/><category term='gfi'/><category term='VM Ware'/><category term='database'/><category term='Windows 7'/><category term='baseline'/><category term='gpmc'/><category term='Certified Ethical Hacker'/><category term='Fine-Grained Password Policies'/><category term='radio'/><category term='Certification'/><category term='knowledge base'/><category term='connect'/><category term='Site Filtering'/><category term='AppLocker'/><category term='Granular Password Settings'/><category term='deployment'/><category term='videos'/><category term='gpedit.msc'/><category term='Security Filtering'/><category term='Client Side Extensions'/><category term='virtual server'/><category term='Solution Accelerator'/><category term='desktop optimization pack'/><category term='sysprep'/><category term='multilingual'/><category term='gpoguy.com'/><category term='sid'/><category term='ctp'/><category term='Linux'/><category term='gpedit'/><category term='server'/><category term='microsoft'/><category term='DesktopStandards'/><category term='multihomed'/><category term='article'/><category term='administrative templates'/><category term='u2'/><category term='password'/><category term='problem'/><category term='BitLocker'/><title type='text'>Comments on heidelbergit: Unique passwords on local user accounts using VBS ...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.heidelbergit.dk/feeds/6586919536619604025/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html'/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-21992565.post-6267463106693581521</id><published>2009-12-30T23:05:54.649+01:00</published><updated>2009-12-30T23:05:54.649+01:00</updated><title type='text'>Great tip Davey ;-)</title><content type='html'>Great tip Davey ;-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/6267463106693581521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/6267463106693581521'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html?showComment=1262210754649#c6267463106693581521' title=''/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html' ref='tag:blogger.com,1999:blog-21992565.post-6586919536619604025' source='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1241537759'/></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-8813996870274898803</id><published>2009-12-30T18:25:16.931+01:00</published><updated>2009-12-30T18:25:16.931+01:00</updated><title type='text'>If you set the permissions on the file share sligh...</title><content type='html'>If you set the permissions on the file share slightly differently then you can reduce the risk of having someone run as local system and see all the machine passwords.&lt;br /&gt;&lt;br /&gt;Set Domain Computers to have the following permissions.  (Apply onto This folder only)&lt;br /&gt;Traverse Folder, List folder, Read Attributes, Read Extended Attributes, Create Files, Read Permissions&lt;br /&gt;&lt;br /&gt;Set Creator Owner full control Files Only.&lt;br /&gt;&lt;br /&gt;Then the computer can create its own file but not read the log from any other machine.&lt;br /&gt;&lt;br /&gt;Also if you enable ABE (Access based enumeration) on the share then each machine will only be able to see its own log files.&lt;br /&gt;&lt;br /&gt;Helps to increase the security a bit.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/8813996870274898803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/8813996870274898803'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html?showComment=1262193916931#c8813996870274898803' title=''/><author><name>Davey</name><uri>http://www.blogger.com/profile/15717963666351852147</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html' ref='tag:blogger.com,1999:blog-21992565.post-6586919536619604025' source='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1327809783'/></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-1313653153180835433</id><published>2009-07-08T20:42:41.594+02:00</published><updated>2009-07-08T20:42:41.594+02:00</updated><title type='text'>Jakob, I really like your approach. I&amp;#39;ve done ...</title><content type='html'>Jakob, I really like your approach. I&amp;#39;ve done something similar that scrambles the password on every reboot, but logging to a central log file file is a nice touch.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/1313653153180835433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/1313653153180835433'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html?showComment=1247078561594#c1313653153180835433' title=''/><author><name>jnelson35</name><uri>http://www.blogger.com/profile/11041299207189698892</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html' ref='tag:blogger.com,1999:blog-21992565.post-6586919536619604025' source='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1767270317'/></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-518374446560252383</id><published>2009-06-04T21:28:18.169+02:00</published><updated>2009-06-04T21:28:18.169+02:00</updated><title type='text'>BTW - from my testing, the script works perfectly ...</title><content type='html'>BTW - from my testing, the script works perfectly on Windows 7 with UAC enabled - Vista UAC suxx :)&lt;br /&gt;&lt;br /&gt;Best regards&lt;br /&gt;Jakob</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/518374446560252383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/518374446560252383'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html?showComment=1244143698169#c518374446560252383' title=''/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html' ref='tag:blogger.com,1999:blog-21992565.post-6586919536619604025' source='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1241537759'/></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-8757449842225664385</id><published>2009-06-04T21:18:29.853+02:00</published><updated>2009-06-04T21:18:29.853+02:00</updated><title type='text'>Hi Derek,

I believe it&amp;#39;s UAC making trouble -...</title><content type='html'>Hi Derek,&lt;br /&gt;&lt;br /&gt;I believe it&amp;#39;s UAC making trouble - both with the C-root write issue and the PWD set issue...&lt;br /&gt;&lt;br /&gt;Please look at this if you have Vista UAC enabled in the environment:&lt;br /&gt;&lt;br /&gt;http://www.winhelponline.com/articles/185/1/VBScripts-and-UAC-elevation.html&lt;br /&gt;&lt;br /&gt;Please let me know whether that fixes the problem or not.&lt;br /&gt;&lt;br /&gt;CYA!&lt;br /&gt;Jakob</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/8757449842225664385'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/8757449842225664385'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html?showComment=1244143109853#c8757449842225664385' title=''/><author><name>Jakob H. Heidelberg</name><uri>http://www.blogger.com/profile/05947807953068058636</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html' ref='tag:blogger.com,1999:blog-21992565.post-6586919536619604025' source='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1241537759'/></entry><entry><id>tag:blogger.com,1999:blog-21992565.post-1435419835063742151</id><published>2009-06-04T14:38:13.398+02:00</published><updated>2009-06-04T14:38:13.398+02:00</updated><title type='text'>This is a great theory for a script, thanks.  Alth...</title><content type='html'>This is a great theory for a script, thanks.  Although I&amp;#39;m having a bit of an issue with it.  I have made my modifications to the script regarding the days (changed to 90), the path for local and the path for network. The admpwd.log file gets created,  but it never creates the stamp file.&lt;br /&gt;&lt;br /&gt;I&amp;#39;m running on Vista, and at first, it gave me an access denied error when trying to create the log files in the root of C.  I created a subdirectory in C and got past that.  &lt;br /&gt;&lt;br /&gt;Here is the error from the admpwd.log -&lt;br /&gt;&lt;br /&gt;2009-06-04 08:31:25 [STARTED]&lt;br /&gt;2009-06-04 08:31:25 [VARIABLES - A]&lt;br /&gt;2009-06-04 08:31:25  - intDays          : 90&lt;br /&gt;2009-06-04 08:31:25  - strNetShare      : &amp;#39;\\server\share\&amp;#39;&lt;br /&gt;2009-06-04 08:31:25  - strLocalLog      : &amp;#39;C:\admin\admpwd.log&amp;#39;&lt;br /&gt;2009-06-04 08:31:25  - strLocalStamp    : &amp;#39;C:\admin\admpwd.stp&amp;#39;&lt;br /&gt;2009-06-04 08:31:25  - strLocalUser     : &amp;#39;zzadmin&amp;#39;&lt;br /&gt;2009-06-04 08:31:25  - strComputer      : &amp;#39;computername&amp;#39;&lt;br /&gt;2009-06-04 08:31:25  - strNetFile       : &amp;#39;\\server\shares\computername.log&amp;#39;&lt;br /&gt;2009-06-04 08:31:25 STATUS  - No local stamp file, probably first run&lt;br /&gt;2009-06-04 08:31:25 SUCCESS - ALIVE:\\server\share\&lt;br /&gt;2009-06-04 08:31:25 [VARIABLES - B]&lt;br /&gt;2009-06-04 08:31:25  - intPasswordLength: 8&lt;br /&gt;2009-06-04 08:31:25  - intWantNumbers   : 1&lt;br /&gt;2009-06-04 08:31:25  - intWantLcase     : 1&lt;br /&gt;2009-06-04 08:31:25  - intWantUcase     : 1&lt;br /&gt;2009-06-04 08:31:25 SUCCESS - PWD written to: &amp;#39;\\server\share\computername.log&amp;#39;&lt;br /&gt;2009-06-04 08:32:00 FAILURE - PWD NOT SET for &amp;#39;zzadmin&amp;#39;&lt;br /&gt;2009-06-04 08:32:00 [ABORTED]</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/1435419835063742151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/21992565/6586919536619604025/comments/default/1435419835063742151'/><link rel='alternate' type='text/html' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html?showComment=1244119093398#c1435419835063742151' title=''/><author><name>Derek</name><uri>http://www.blogger.com/profile/16281477783984033350</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.heidelbergit.dk/2009/05/unique-passwords-on-local-useraccounts.html' ref='tag:blogger.com,1999:blog-21992565.post-6586919536619604025' source='http://www.blogger.com/feeds/21992565/posts/default/6586919536619604025' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1359950044'/></entry></feed>
