Password Synchronization DLL built by Thor Technologies
Originally Published: 2004-08-31
Article Number
Applies To
Password Synchronization DLL
Issue
Resolution
- How closely does it adhere to Microsoft standards?
The .DLL uses Microsoft's standard calls for "password filters". The standard is defined by Microsoft, and defines the interface for the call that has to be followed by the filters for them to work. The installation and format are all based on Microsoft definitions.
- What happens to intercepted password changes? Are they left in memory on the DC for a hacker or to be hijacked?
The .DLL encodes the user and password, and calls a batch file provided by Thor. After that, the memory used by the password is set to zeros, and de-allocated. The only thing left in memory are zeros.
- What happens to intercepted password changes for unknown users?
The change API for Xellerate is called and if the user does not exist, an exception is thrown and it is logged, but nothing happens in Xellerate.
- Are the passwords sent in clear text or are they encrypted or sent in a secure tunnel?
The normal Xellerate API's are called, to the data is sent encrypted to Xellerate.
Related Articles
Can Built-in Attributes Be Pruned to Improve Performance in RSA Web Threat Detection 6.0? 2Number of Views RSA SecurID Access: Identify Java Authentication API version/build 85Number of Views Trying to get a MSI package built to deploy SA SFTP Agent via SCCM. 37Number of Views RSA SDK 4.0 (Build 4.0.3) for Android Developer's Guide and Release Notes 258Number of Views RSA SDK 4.0 (Build 4.0.7) for iOS Developer's Guide and Release Notes 173Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service LDAP password authentication failed - Logon failure: unknown username or invalid password when attempting RADIUS authentic…
Don't see what you're looking for?