Very nice write up! I am one of the founders of
www.plain-text.info and I still feel people do not listen to the fact weak passwords is negligence. I do want to add one thing. You explained how NTLM is better and LM (true) and that users should migrate over to NTLM. I agree it's the right way to go but remember to that LM is still around because networks and domains still have Windows 9X & NT PC's on there domains. If you force you domain/LAN to only NTLM you will push out all the older M$ PC's. Anyway nice paper and good luck on you keeping the Trojans out. I just opened a new web site (
www.anti-hacker.info) and I get all kinds of kiddies hitting it.
Slimjim100
www.anti-hacker.info