Archives
 
 
 
  Special
 
 
 
  About Us
 
 
 

Newsletter
Free E-mail Newsletter from BYTE.com

 
    
           
Visit the home page Browse the four-year online archive Download platform-neutral CPU/FPU benchmarks Find information for advertisers, authors, vendors, subscribers Request free information on products written about or advertised in BYTE Submit a press release, or scan recent announcements Talk with BYTE's staff and readers about products and technologies

ArticlesNT Security


May 1997 / Inbox / NT Security

In "NT Security" (February Web Project) Jon Udell mentioned that the Windows NT 4 Resource Kit includes a utility to activate lockout for the administrator account. Can you be more specific and provide the name?

J. Rodney Grisham
Houston, TX
grisham@neosoft.com

This command-line utility is called PASSPROP and can be used to set two domain policy flags: whether passwords must be complex, and whether the administrator account can be locked out. For details on syntax and usage, run "passprop," with no parameters, at the command prompt. -- Jon Udell, executive editor

I enjoyed "NT Security" even though I don't use NT machines. One nit: You said a router would only have to allow TCP ports 80 and 21 into the server. Most FTP servers support the PASV command, and a number of firewalls no w require that their clients use it. This implies that you must allow the incoming TCP connections for the second channel to the FTP server. I have no idea if the NT FTP server chooses the PASV port in a predictable way, but the router rules would have to allow whatever incoming ports were needed.

Bill Cheswick
Bell Laboratories
ches@bell-labs.com

Thanks for pointing that out. It does complicate matters, since the inbound port seems to be chosen at random. I should have subtracted FTP from the example. -- Jon Udell, executive editor

In "NT Security" you ask for a way to suppress the connection banner when logging onto a Windows NT FTP server. I took the challenge. I found the message in the file FTPSVC.DLL. I copied the file to a DOS system, examined it with Norton Utilities, found the messages, replaced the characters with spaces, saved the file, and copied it back to the NT System root area (you have to stop the FTP server-service to do this). Y ou can replace the original message -- Windows NT FTP Server (%s) -- with anything within that number of characters (27).

Halvard Gomo
Ulset, Norway
gomo@online.no

Thanks! It'd be nice for Microsoft to make that a registry setting, wouldn't it? -- Jon Udell, executive editor


Up to the Inbox section contentsGo to previous article: Platform AgnosticsGo to next article: Clean Data InSearchSend a comment on this articleSubscribe to BYTE or BYTE on CD-ROM  
Flexible C++
Matthew Wilson
My approach to software engineering is far more pragmatic than it is theoretical--and no language better exemplifies this than C++.

more...

BYTE Digest

BYTE Digest editors every month analyze and evaluate the best articles from Information Week, EE Times, Dr. Dobb's Journal, Network Computing, Sys Admin, and dozens of other CMP publications—bringing you critical news and information about wireless communication, computer security, software development, embedded systems, and more!

Find out more

BYTE.com Store

BYTE CD-ROM
NOW, on one CD-ROM, you can instantly access more than 8 years of BYTE.
 
The Best of BYTE Volume 1: Programming Languages
The Best of BYTE
Volume 1: Programming Languages
In this issue of Best of BYTE, we bring together some of the leading programming language designers and implementors...

Copyright © 2005 CMP Media LLC, Privacy Policy, Your California Privacy rights, Terms of Service
Site comments: webmaster@byte.com
SDMG Web Sites: BYTE.com, C/C++ Users Journal, Dr. Dobb's Journal, MSDN Magazine, New Architect, SD Expo, SD Magazine, Sys Admin, The Perl Journal, UnixReview.com, Windows Developer Network