11 Replies Latest reply on Jul 1, 2014 8:42 AM by oleg.zastavnyi

    Blank Passwords

    asmalley

      I fired up AlertCentral 1.1.6 for the first time today. I went through the setup and got all green checks and I was able to log in and do a lot of configuration.

       

      When I logged out of the admin account and I tried logging in with my AD account, I accidentally noticed that I'm able to successfully authenticate using domain\username and a blank password. I tried with an incorrect password and I get an authentication error.  I can also get in by using the correct password (as expected).

       

      I do see bad password counts increment on my AD account and I do lock myself out after I hit the threshold, but I can still get into Alert Central with no problem.

       

      I also noticed that I can authenticate using my AD account without having domain\ on the front of it. I'm fine with that, just thought I'd mention it.