Home > Domino Tips > Spam and Security > Back Door To Password Recovery
Domino Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SPAM AND SECURITY

Back Door To Password Recovery


Mike Andrews
08.01.2000
Rating: -3.75- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


As I see it, the only way for an Admin to restore a forgotten password using
the R5 Password Recovery feature is to open the recovery mail-in database,
detach the encrypted ID, extract the recovery password(s) and get the ID onto
the client's system. For various reasons, it is often difficult to get an ID
onto the client's system without physically walking a floppy disk to the
client's office. I believe the documentation suggests "sending the ID to the
client". If the client forgot his password, he cannot access his mail file, so
this must mean sending a copy to a neighbor, which is in itself a huge security
risk.

In the interest of saving Admin time (and getting a Dog Pound golf shirt), here
is a back door to password recovery:

1. The Admin detaches the encrypted ID from the mail-in database and extracts
the recovery password as always (detach to local drive-use
administrator-configuration tab-tools-certif

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Spam and Security
Securely connect Lotus Domino servers on different domains
Protect Lotus Notes from malicious code with the Domino ECL
How to correct Lotus Notes public key mismatches in four easy steps
A recipe for secure IM success
Telecommuter security kit
Spear phishing: Don't be a target
FAQ: Lotus Notes Domino password issues
Security awareness training: How to educate employees about spyware
Seven tips to strengthen your Domino e-mail security
Admin2005 preview: Tips, techniques, and a look at Notes/Domino Rel. 7

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


ication-extract recovery
password). Admin writes down the password and phones the client.
2. The client launches Notes and Notes asks for his password (which he has
forgotten).
3. From the "Enter Password" window the client presses ESC twice which takes
him to the "Choose User ID to Switch to" window.
4. The client double-clicks his ID, which takes him back to Step 2.
5. This time, he presses ESC once from "Enter Password" window, which takes him
to the "Choose User ID to Switch to" window.
6. The client double-clicks his ID, which now takes him to the "Enter Passwords
for admin recovery passwords" window.
7. The client enters the recovery password(s) that the Admin dictates over the
phone.
8. The client enters and confirms a new password and has recovered use of his
ID without a visit from Admin or his neighbor.

It sounds quite complicated but is really quite easy and does save a ton of
time for Admins!

Rate this Tip
To rate tips, you must be a member of SearchDomino.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Domino & Lotus Notes Security Solutions: Authentication, Antispam, Encryption and Antivirus
HomeTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersDomino IT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 1999 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts