Getting Started

Security experts from industry, government, and academia agree that weak passwords represent one of the ten most critical internet security threats,1 and are receiving more attention as a source of vulnerability, both on client desktop computers and in networks. LC5 identifies and assesses password vulnerability over local machines and networks in a streamlined application, with built-in reports and remediation tools.

LC5 uses a variety of sources and methods to retrieve passwords from the operating system. Feedback about the strength of passwords is based upon the types of audit required to recover the password, and the length of time required for the audit. LC5 is a state of the art tool for password auditing and recovery that serves to guide organizational policies and procedures.

System administrators audit passwords to determine the strength of the passwords used on client machines and network access. Weak passwords, such as a password using all lower case letters, represent vulnerability points for any organization. Administrators use corporate password policies and filtered password generators to improve the quality of passwords used in their organizations. But without testing the passwords against a real world password auditor, the administrator risks the chance passwords can be uncovered by an external attacker or malicious insider.

In other cases, LC5 can be used to streamline the migration or upgrading of users from one authentication system to another. Administrators can also use LC5 to recover lost or forgotten passwords, and permit re-entry to a locked out system.

LC5 is available in the following versions:


FEATURE


PROFESSIONAL


ADMINISTRATOR


SITE


CONSULTANT

Password assessment

n

n

n

n

Password recovery

n

n

n

n

Dictionary support

n

n

n

n

Hybrid support

n

n

n

n

Brute force support

n

n

n

n

International character support

n

n

n

n

Wizard-based GUI

n

n

n

n

Password quality scoring

n

n

n

n

Remediation

n

n

n

n

Windows support

n

n

n

n

UNIX support

n

n

n

n

Enhanced reporting

n

n

n

n

Remote system scans

n

n

n

n

Pre-computed passwords

 

n

n

n

Assessment scheduling

 

n

n

 

Site-wide installations

 

 

n

 

Multi-client assessments

 

 

 

n

Perpetual use

n

n

n

1 year

Unlimited accounts

n

n

n

n

Installing LC5

To install LC5:

1.      LC5 is distributed in a self-installing executable distribution file that can be downloaded for free at http://www.atstake.com/lc.

2.      Save the .ZIP file to your desktop.

3.      Open the .ZIP file and extract the contents to a temp directory.

4.      In the temp directory, click the lc5set.exe file. InstallShield starts a standard installation process. At the Welcome screen, click Next.

 

 

5.      InstallShield copies LC5 files on to your system.

 

 

6.      Read the License Agreement screen, then click Yes to agree.

 

 

7.      InstallShield installs LC5 in a default installation location:

 

\Program Files\@stake\LC5

 

or you may Browse to choose a different location. Click Next when ready.

 

 

8.      Choose the type of setup for LC5. The default is Typical, which installs the most common options. You may also choose Compact to install the minimum required options, or Custom to choose specific options. Click Next when ready.

 

 

9.      A shortcut to the LC5 executable is installed in the Programs folder under the Start menu. The default folder name is LC5. You may choose a different name. Click Next when ready.

 

 

10.  InstallShield now installs components on to your system.

 

11.  Click Finish when InstallShield completes the installation.

 

 

12.  LC5 is now installed on your system. Click the Start button, and go to the Programs folder to run LC5.

Uninstalling LC5

To uninstall LC5:

1.      In the Windows Control Panel, open Add/Remove Programs.

 

2.      Select LC5 from the list of programs installed on your system.

 

3.      An InstallShield window gives you the choice to Modify, Repair, or Remove LC5. Click Remove, and then click Next.

 

 

4.      Confirm that you want to delete the files by clicking OK.

 

 

5.      When InstallShield has completed the removal, click Finish.

 

 

6.      LC5 is now removed from your system.

Remote Manual Installation of LC Agent

To manually install the LC Agent on a remote machine, use a Command screen, and follow the instructions below:

  1. Select Create Remote Agent in the File menu.
  2. A Warning dialog informs you that this regenerates a public key and embeds it in the lcagent.exe file. It also breaks communication between other remote machines. Click Yes to create the remote agent.
  3. Copy lcagent.exe from your LC5 directory to the target machine.
  4. From a command prompt, locate the directory you copied lcagent.exe on the remote machine, then run the install as follows:

      lcagent.exe /install

  5. To remove the LC Agent, use the command prompt with the following command:

      lcagent.exe /remove

  6. Delete the .exe file.

Registering LC5

@stake offers a 15 day free trial period for LC5, providing access to the basic auditing features for 10 user accounts. The following are unavailable in the trial version:

  • Brute force crack
  • Pre-computed crack
  • Audit scheduling

Registered versions of LC5 provide an Unlock Code allowing continued use of the product, as well as features available only in the LC5 Administrator version.

@stake offers registration online, by telephone, fax, and online. Click here for phone and fax numbers, and the online registration form.

LC5 is licensed on a per machine basis, and each machine generates its own unique LC5 Serial Number. When registering, provide your name, address, credit card information, email address, and the LC5 Serial Number.

Note: The Serial Number is obtained from your installation. You must download and install LC5 to before you can register it.

To obtain the LC5 Serial Number, launch LC5, and click Register from the LC5 splash screen. The Registration dialog box provides you a Serial Number. When you register, you receive a unique Unlock Code for your installation. Enter this code in the LC5 Registration dialog to unlock the product.

Reinstalling LC5

To reinstall LC5 on new machine or operating system, you will need to obtain a new Unlock Code. Install LC5 on the new system, then copy the installation's Serial Number, from the About dialog in the Help menu or from the Splash screen that appears when LC5 is launched. Click here or go to http://www.atstake.com/lc/reinstall.html and obtain an Unlock Code for your new installation.

 

Note: Unlock Codes are unique to each individual system, and one code does not work for other systems.

  

                                                                                 Next: What’s New in LC5


[1] The SANS Institute. Ten Most Critical Internet Security Threats - The Experts' Consensus. January, 2001.