Windows Scripting
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
 
User Name:
Password:
Remember me
Go Back   ASP Free ForumsSystem AdministrationWindows Scripting

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread ASP Free Forums Sponsor:
  #1  
Old October 16th, 2009, 11:30 AM
deviousdexter deviousdexter is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2009
Posts: 4 deviousdexter User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 54 m 23 sec
Reputation Power: 0
WSH - Clear cached passwords

Hi

Need a little help to clarify a problem here if possible.

My script currently locks the workstation remotely.
I need to have my script change the password of a logged in user and clear the cache so that once it is locked they cannot log back in with the old ( cached ) password.

I do not want to use GPO to stop the system caching passwords as this may prove detrimental in the event of a domain login failure.

Does anyone know of a way to clear the cache remotely from a script ?

thanks in advance

Reply With Quote
  #2  
Old October 17th, 2009, 04:52 AM
Nilpo's Avatar
Nilpo Nilpo is offline
ASP Free Intermediate (1500 - 1999 posts)
 
Join Date: Jun 2006
Location: Salem, OH
Posts: 1,880 Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)Nilpo User rank is General (90000 - 100000 Reputation Level)  Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1Folding Points: 214558 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 1 Week 2 Days 8 h 47 m 8 sec
Reputation Power: 967
Send a message via ICQ to Nilpo Send a message via AIM to Nilpo Send a message via MSN to Nilpo Send a message via Yahoo to Nilpo Send a message via Google Talk to Nilpo Send a message via Skype to Nilpo Send a message via XFire to Nilpo
Facebook MySpace Orkut
You're asking for a way to circumvent built-in securities there, "devious"dexter. I'm not even going to take a look into this without a good reason why you would need to do such thing.
__________________
Don't like me? Click it.

Scripting problems? Windows questions? Ask the Windows Guru!

Stay up to date with all of my latest content. Follow me on Twitter!

Help us help you! Post your exact error message with these easy tips!

Reply With Quote
  #3  
Old October 17th, 2009, 07:42 PM
deviousdexter deviousdexter is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2009
Posts: 4 deviousdexter User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 54 m 23 sec
Reputation Power: 0
HI Nilpo and thanks for taking the time to answer

i understand your concern however my issue is this - i have a scrip that will lock the users workstation and change their password. However as the cached password is still sctive until a user logs in with the new password they still have access to the workstation.
I am trying to stop this from happening - this, as far as i can see, requires flushing the cache of their last password to stop this being a security issue.
if i set the password cache to store 0 last logins it will affect all users which is not my intention, and would cause problems should the server go offline.
I could not find a setting on win2k GPO's to force server authentication on workstation unlock. if you can point me to this GPO, this would serve the purpose i need.
many thanks

Reply With Quote
  #4  
Old October 22nd, 2009, 02:47 PM
deviousdexter deviousdexter is offline
Registered User
ASP Free Newbie (0 - 499 posts)
 
Join Date: Oct 2009
Posts: 4 deviousdexter User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 54 m 23 sec
Reputation Power: 0
Well i think i have found a workaround for this which does not compromise built in security features, if anyone is interested.

By adding a value to the registry, the machine can be made to authenticate every time it is unlocked - thius is available in later versions of windows server through GPO's but i could not find it in standard win2k server GPO's.

this works on Windows 2000 Server and a Windows 200o Pro client.

NOTE: Playing about with the registry can render your machine un useable please read up before trying this key or modifying it in anyway.

find this key :-

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\Currentversion\Winlogon

add a DWORD entry called ForceUnlockLogon
change the value to 1

------

this should now force the machine to authenticate when unlocking.

i believe from what i have read that exceptions can occur when screen savers are active but have not pursued this as of yet.

I would be interested if anyone could point me to a useful article on adding this into .adm files ( i think it requires the system.adm to be modified but cant see a clear article on actually achieving this)

thanks

Reply With Quote
Reply

Viewing: ASP Free ForumsSystem AdministrationWindows Scripting > WSH - Clear cached passwords


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump





 Free IT White Papers!
 
How to Present Effectively Online
This white paper offers practical and actionable advice on the key steps that any presenter should consider as they plan and execute a Webinar or online meeting.

 
Open Source Security Myths
Open Source Software (OSS) is computer software whose source code is available to the general public with relaxed or non-existent intellectual property restrictions (or arrangement such as the public domain), and is usually developed with the input of many contributors.

 
Power and Cooling Capacity Management for Data Centers
This paper describes the principles for achieving power and cooling capacity management.

 
Scalable, Fault-Tolerant NAS for Oracle - The Next Generation
For several years NAS has been evolving as a storage alternative for Oracle databases, and for good reason: NAS is quite often the simplest, most cost-effective storage approach for Oracle. Learn about the benefits that HP's approach to scalable NAS brings to Oracle environments in this comprehensive white paper.

 
Understanding Web Application Security Challenges
This white paper discusses many common threats and preventive measures for Web application security, and explains what you can do to help protect your organization.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2009 by Developer Shed. All rights reserved. DS Cluster 4 Hosted by Hostway
For more Enterprise Application Development news, visit eWeek