Guest Spin Posted August 31, 2008 Posted August 31, 2008 Gurus, Has anyone ever heard of a local LSA secrets file on a Windows workstation being compromised? -- Spin Quote
Guest S. Pidgorny Posted September 1, 2008 Posted September 1, 2008 Re: Has anyone ever heard of a local LSA secrets file on a Windowsworkstation being compromised? LSA Secrets are not secured. It may take a while to brute force individual entries though. -- Svyatoslav Pidgorny, MS MVP - Security, MCSE -= F1 is the key =- http://sl.mvps.org http://msmvps.com/blogs/sp Spin wrote:<span style="color:blue"> > Gurus, > > Has anyone ever heard of a local LSA secrets file on a Windows workstation > being compromised? > > -- > Spin > > > </span> Quote
Guest Spin Posted September 1, 2008 Posted September 1, 2008 Understood. They exist in plain text inside the LSA Secrets memory process. One would need to attack that to dump the entries. By default, one needs SecDebugProcess right in order to do so, by default this is only granted to Administrators. Which is why one needs to secure the local admin account and all members of the Administrators to the best of their abilities. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.