Checksum of the Machine Account Password

Posted By:      Posted Date: April 14, 2011    Points: 0   Category :.NET Framework

I would like to be able to obtain a checksum, hash value or the actual machine account password for a Domain computer.  A C# application can be run on the computer itself with administrative privileges.  Perhaps I need to be asking a different question, but an authorized computer can drop out of a Domain and prevent user logins.  I want to be able to determine if the machine account password has just been changed or has stayed the same in order to help debug what is happening when a computer falls out of sync with the Domain.  Thanks.


Managed Account Password Changes Failing

<!-- [if gte mso 10]> <mce:style> I was troubleshooting a problem with the Profile Sync Service and discovered some permission problems.  I noticed that my monthly timer job (which is running daily now) for generating new passwords is failing.  Watching ULS while manually running the job returned some curious records. At the end of the list was an Access is Denied error which I assume – but am not convinced – is the problem.  The w3wp process is running under the farm admin account which is an db_owner of the SP_Config database.  If it needs more perms, please let me know what they are. There were other strange records returned by the ULS in the Database category.  These are, in order There was a warning that “A large block of literal text was sent to sql…” Slow Query Duration: 43.39… Slow Query Stack Trace-Managed:… ConnectionString: ‘Data Source=xxx;Initial Catalog=SP_Config…” and now for the winner SqlCommand: ‘BEGIN TRAN; EXEC … The SqlCommand had 78,111 characters (not an exaggeration) and is clearly malformed.  There was a single-quoted string:   ‘… EXEC @PutDepReturnValue = dbo.proc_putDependency @ObjectId0, @DependantId; IF (@PutDepReturnValue <> 0) BEGIN ROLLBACK TRAN; RETURN; END EXEC @PutDepReturnValue = dbo.proc_putDepend

managed account password changes with a RODC

We are using sharepoint 2010 with a RODC,  I was informed that we needed to changed the Farm Admin password, since the we are using the RODC I cannot cahnge the PW in sharepoint, I have to change the PW by having a Doamin Admin change the AD account password, then in  central admin > managed Accoutnts I use this "To set the stored password value to a current known value, select use existing password and enter a password value."  I can log on with the new password and it says welocme system account...  eveything seems to work..,  EXCEPT the lookup to "select people and groups" that are using FORMS Auth, I can now only get the NT Auth users and groups. How do I change the paswwords using a RODC and have everything work???

Remote copy and execution given admin username and password for remote machine



I have an application (.exe files) that I need to install on remote machine. For this I need to copy .exe file from my machine A remote machine B  and execute it remotely.

I have local administrative privilleges on remote machine.

For e.g. Username & password on remote machine : "remoteAdmin" , "remotePassword".

However this "remoteAdmin" account is not present in my local admin group on my machine A.

Is there a way to do this ?

Also on remote machine B firewall may be on or off.

I tried this using WMI but there were some issues due to firewall.

I can do this using File.Copy method of System.IO namespace but it needs "remoteAdmin" account to be present in my local machine's (A) Administrators group. I have even tried creating new user account and adding to admin goup using DirectoryServices but I don't know how to set domain for the new account.

Also for remote execution I tried using wmic but it did not work when firewall was on. Iteried remotely running notepad.exe. It works if firewall is off but I cannot assume that firewall would be always off.

So , is there a way to copy file and remotely execute them if I have admin username and password for remote machine ( preferable using C++ or C#) ?

 Also I cannot

Password prompt with R2 on a separate machine



I am able to access report manager and service URLs locally on a machine running SQL 2008 R2, but when I try openning either of those URLs from another machine under where I am logged under the same user name, I am getting endless password prompts and unable to log in.

The IE machine is 2003 R2, the server is 2008 R2.

What is wrong here?


SA account password issue


Hello and thank you to all who is willing to provide some insight.  I am running MOSS 2007 with a backend of SQL 2008.  I am receiving 'Failure Audit' messages in my Application Event Viewer (Windows 2003 x64).  It shows the famous 'Event ID: 18456 which from what I have researched can be just about anything.  I have nothing running under the sa account (I really did not setup my MOSS intranet site but I have taken it over).  I dont even have an sa account in AD?  So what I was wondering is if I simply change the password in SQL, will I blow everything up?  I do not know where to begin, so please ask me whatever you want and I will do my best to answer.


How to Encrypt and Decrypt a Password using SQLSERVER 2005?(Video)

Encypt and Decrypt a Password using SQLSERVER 2005(Video)

symmetric key protected by a password

An alternative could be using a symmetric key protected by a password, as long as your application generates the CREATE SYMMETRIC KEY and OPEN SYMMETRIC KEY statements directly instead of calling them inside a SP (otherwise the password will still be passed as a parameter, and will be in clear in the profiler).

SqlServer - Windows Account to install Application from Gallery


Referring to this tutorial: http://www.asp.net/webmatrix/tutorials/download-and-install-an-asp-net-application

I selected umbraco cms and got this wizard:

I already have Standard Sql Server 2005 on my machine which I wanted to us for above DB and not SqlExpress.

I did not remember "sa" account pwd nor I use explicitly any account to connect to my Sqlserver. I use Windows Authentication account i.e implicit authentication. So I created new account and gave all rights and used it in the above wizard and was able to install the database after some struggle.

My question is: What if I want to use my Windows Account to install the database above? Why the wizard don't have any option to use Windows Integrated Authentication?

Note: I can create the DB with external user I created, just looking specifics for using Windows Authentication for above installation.

Wrong Account being used to access files - Help - No Impersonation


I run a simple .aspx website on a Windows Server 2008 machine.

There is NO impersonation, and System.Security.Principal.WindowsIdentity.GetCurrent().Name returns NT AUTHORITY\NETWORK SERVICE, which it the account which the application pool runs. In my web.config, I have <authentication mode="Forms">.


I tried to test the security of the application and server by removing file permissions to the .aspx files. I was greatly worried when the website continued to run without problem (it should not have been able to read the .aspx files).

By turning on file level auditing, I discovered that the .aspx files were being read by the machine$ account (if the machine is called Serv1, then the files would be read by the Serv1$ account, which seems to have access to all files on the local machine).


Is this a security breach or is this behaviour by design ?

Please can somebody assist, as I am worried.

ASP.Net account deleted. How to create it again?


 Hi I have created an intranet application using ASP.Net/IIS.

I normally need to web share the folder and allow full permission to ASP.Net user account.

However, I carelessly deleted this account. How to create it again ?

Pls help.... thanks.


Use Membership but bypass / disable password usage for users


I have an application that does LDAP authentication. The authentication is done on the code behind page of my Login.aspx page. Once the user passes LDAP authentication, a cookie is set and I redirect:

FormsAuthentication.RedirectFromLoginPage(UserName.Text, False)

I would like to setup membership in my application and keep track of some user information. But due to company security requirements, I cannot store user passwords on my application. That must stay on the LDAP server only.

Is there a way to store users but disable password storage on the aspnet_membership table?

help needed: Ldap User authentication using userDN and password



Is it possible to authenticate a user using userDN and password? If so, then tell me the syntax.So far i have tried to authenticate using username and password from my c# code using directoryentry which takes the parameters like domainname,username and password. But i need to authenticate using Userdn and password.

Need help using control adapters at the machine level

Hi guys!

Let me explain our situation. I do web development at a university at which we have to meet strict accessibility guidelines. I've specially modified the adapters (as well as extended CompositeDataBoundControlAdapter to include GridView) for use on our site and to use with our global stylesheets as well as compiled the control adapters into a DLL.

The control adapters now all reside in the WebServices.CssFriendlyAdapters DLL.  (For example, WebServices.CssFriendlyAdapters.GridViewAdapter).

Currently, when someone drops an App_Browsers folder in to their site with the adapters specified, the adapters work. However, we'd like to be able to specify this in the C:\WINDOWS\Microsoft.NET\Framework\(version number)\CONFIG\Browsers directory so that the adapters work automatically without anyone having to move anything into App_Browsers for every site. To ensure that someone can still use the "old way" or will not be confused by their controls being adapted, I've written in code that uses the base rendering methods unless xhtmlConformance is set to "Strict" in the site's web.config file.

Anyway, on to the problem. When trying to compile the controlAdapters into the C:\WINDOWS\Microsoft.NET\Framework\(version number)\CONFIG\Browsers directory using aspnet_regbrowsers.exe (see http://msdn2.microsoft.com/en-us/library/ms229858.a

{ End Bracket }: The Emergence Of Machine Translation


Vikram Dendi looks at how machine translation is poised to change the world and why it is so important to deliver information in multiple languages.

Vikram Dendi

MSDN Magazine January 2009

Security: Safer Authentication with a One-Time Password Solution


One-time passwords offer solutions to dictionary attacks, phishing, interception, and lots of other security breaches. Here's how it all works.

Dan Griffin

MSDN Magazine May 2008

Least Privilege: Teach Your Apps To Play Nicely With Windows Vista User Account Control


User Account Control in Windows Vista keeps the OS safe from intentional and accidental configuration changes.

Chris Corio

MSDN Magazine January 2007

Security Briefs: Password Minder Internals


In my last column I introduced Password Minder, the tool I use to manage all of my passwords. It generates a long, random password for each site I visit, and makes it possible for me to use the most complex passwords possible, without ever having to see the actual password material or type it in manually.

Keith Brown

MSDN Magazine October 2004

