Avatier’s New Password Bouncer Automates
Enhanced Security Policy
Acrobat Version (24.5KB)
For Windows NT/2000 system and security administrators concerned
about unauthorized access to user accounts, Avatier’s Password
Bouncer is a centralized management console for preventing vulnerable
passwords from being used by employees and contractors. Unlike
currently existing security products, Password Bouncer defeats
hackers by using their own methods in the on-going battle
to protect your network.
Are Your Employees Unwittingly Leaving Your Enterprise Open
to an Attack?
The security industry has determined that 70% of all deployed firewalls are not effectively protecting the networks behind
them. Most significant, is that 70% of all network compromises occur behind the firewall by a user or hacker attacking other
user accounts.
Majority of users are prone to selecting simple, easy-to-remember passwords containing only letters or digits.
Basic human behavior innocently
reduces the effort required to compromise a password. A smart hacker can
merely apply guesswork to gain
unauthorized network access using spouse and child names, birthdays, anniversaries, etc.
More insidious are freely available utilities that automate what is commonly known
as a "dictionary attack." These programs compare common words from several dictionaries to compromise a user’s
password. If a hacker should gain access to an administrative
password and the Domain Controller’s SAM, all
passwords on the network are threatened -- from the
mailroom to the boardroom.
Using these methods, a hacker can crack virtually any password given enough
processing power and time. The key is to harden the
password, so that by the time it can be compromised, it
has already changed due to proper, globally enforced
password policies.
 Password
Bouncer– Enhanced Password Policy Management and Automated
Enforcement
Security on the network is of paramount importance requiring
the cooperation of everyone from the CEO to the temporary
employee. Although organizations establish and publish strong
password standards that disallow common words and names, they
face the following specific challenges when executing these policies:
-
Native tools in today’s Windows NT/2000 environment do
not provide the ability to enforce a truly strong password
policy on the level required to effectively protect the network. -
Automated systems to compare and validate passwords against illegal wordlists
do not exist.
-
Password Bouncer is the first
solution that streamlines and automates the process of
centrally managing and automatically enforcing an enhanced
password security policy:
- Reject passwords that contain common words using a
300,000-word English wordlist.
- Reject passwords that contain common names using a 4,000-word proper name wordlist.
- Reject passwords that contain specific names or phrases
using a custom wordlist that includes wildcard support.
- Enforce the use of upper and lower case characters (mixed case).
- Enforce the use and position of special characters.
- Enforce the use and position of numeric characters.
- Reject passwords that contain palindromes (i.e. radar or bob).
- Enforce
password length, minimum, and maximum.
- Reject passwords with repeating sequences.
By asserting control over the
weakest link in your security policy, the user password,
Password Bouncer is the single most effective measure that
will improve your internal Windows NT/2000 security.
Get ahead of the hackers and beat them at their own game in
the race to compromise your network – put Password Bouncer to
work today.
|