Javascript must be enabled to continue!
Evaluating Windows Vista user account security
View through CrossRef
In the current Windows version (Vista), as in all previous versions, creating a user account without setting a password is possible. For a personal PC this might be without too much risk, although it is not recommended, even by Microsoft itself. However, for business computers it is necessary to restrict access to the computers, starting with defining a different password for every user account. For the earlier versions of Windows, a lot of resources can be found giving advice how to construct passwords of user accounts. In some extent they contain remarks concerning the suitability of their solution for Windows Vista. But all these resources are not very precise about what kind of passwords the user must use. To assess the protection of passwords, it is very useful to know how effective the widely available applications for cracking passwords. This research analyzes, in which way an attacker is able to obtain the password of a Windows Vista PC. During this research the physical access to the PC is needed. This research shows that password consists of 8 characters with small letter characters and numbers can easily be cracked if it has know usual combinations. Whereas a Dictionary Attack will probably not find unusual combinations. Adding captel letter characters will make the process harder as there are several more combinations, so it will take longer time but is still feasible. Taking into account special characters it will probably take too long time and even most Dictionary Attacks will fail. For rainbow tables the size of the table has to be considered. If it is not too big, even these small passwords cannot be cracked. For longer passwords probably the simplest ones, small letter characters and numbers, can be cracked only. In this case brute force takes too long time in most cases and a dictionary will contain only a few words this long and even the rainbow tables become too large for normal use. They can only be successful if enough limitations are known and the overall size of the table can be limited.
College of Science for Women, University of Baghdad
Title: Evaluating Windows Vista user account security
Description:
In the current Windows version (Vista), as in all previous versions, creating a user account without setting a password is possible.
For a personal PC this might be without too much risk, although it is not recommended, even by Microsoft itself.
However, for business computers it is necessary to restrict access to the computers, starting with defining a different password for every user account.
For the earlier versions of Windows, a lot of resources can be found giving advice how to construct passwords of user accounts.
In some extent they contain remarks concerning the suitability of their solution for Windows Vista.
But all these resources are not very precise about what kind of passwords the user must use.
To assess the protection of passwords, it is very useful to know how effective the widely available applications for cracking passwords.
This research analyzes, in which way an attacker is able to obtain the password of a Windows Vista PC.
During this research the physical access to the PC is needed.
This research shows that password consists of 8 characters with small letter characters and numbers can easily be cracked if it has know usual combinations.
Whereas a Dictionary Attack will probably not find unusual combinations.
Adding captel letter characters will make the process harder as there are several more combinations, so it will take longer time but is still feasible.
Taking into account special characters it will probably take too long time and even most Dictionary Attacks will fail.
For rainbow tables the size of the table has to be considered.
If it is not too big, even these small passwords cannot be cracked.
For longer passwords probably the simplest ones, small letter characters and numbers, can be cracked only.
In this case brute force takes too long time in most cases and a dictionary will contain only a few words this long and even the rainbow tables become too large for normal use.
They can only be successful if enough limitations are known and the overall size of the table can be limited.
Related Results
Alts and Automediality: Compartmentalising the Self through Multiple Social Media Profiles
Alts and Automediality: Compartmentalising the Self through Multiple Social Media Profiles
IntroductionAlt, or alternative, accounts are secondary profiles people use in addition to a main account on a social media platform. They are a kind of automediation, a way of rep...
Malware and Windows APIs: A Dangerous Duo
Malware and Windows APIs: A Dangerous Duo
This paper introduces its interaction with malware and Windows APIs (application programming interface). The first section describes malware and investigates various types such as ...
Development Tasks of AI-based Security Industry
Development Tasks of AI-based Security Industry
Recently, the government's interest in industries utilizing AI has been amplified, with initiatives such as announcing a roadmap aiming to achieve the goal of becoming the world's ...
Analisis Komparatif Sistem Keamanan Windows 7 Dan Windows 8
Analisis Komparatif Sistem Keamanan Windows 7 Dan Windows 8
The operating system is a vital part of the computer system. Windows users still occupies the top position in the operating system user statistics. The popular Windows operating sy...
Analisis Komparatif Sistem Keamanan Windows 7 Dan Windows 8
Analisis Komparatif Sistem Keamanan Windows 7 Dan Windows 8
The operating system is a vital part of the computer system. Windows users still occupies the top position in the operating system user statistics. The popular Windows operating sy...
Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework
Study of bypassing Microsoft Windows Security using the MITRE CALDERA Framework
Background:
Microsoft Windows Security is a recently implemented safeguard for the Windows operating systems, including the latest versions of Windows10 and 11....
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
“Essential Security Practices for Fortifying Mobile Apps” is a definitive guide designed to empower developers, security professionals, and organizations with the knowledge and too...
Human Security
Human Security
The term “human security” was first employed in the United Nations Development Programme (UNDP) Human Development Report (HDR) of 1994, which argued for a “people-centric” concept ...

