change passwords via LDAP

From: Gabriel Kuri (gkuri_at_CSUPOMONA.EDU)
Date: 05/01/03

  • Next message: http-equiv_at_excite.com: "SILLY BEHAVIOR Part II : Internet Explorer 5.5 - 6.0"
    Date:         Wed, 30 Apr 2003 22:26:06 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Windows 2000 Server has the ability to change user's passwords
    in Active Directory via the LDAP interface. However, we've found this
    functionality was broken in a patch Microsoft released
    that is associated with security bulletin MS01-036,
    and then later superseded by MS02-016.

    We have implemented one time password synchronization between
    our UNIX environment and Windows environment by changing
    the Windows password via the LDAP interface. This
    functionality, however, has been broken for several
    months, and not until this week have we been able
    to track it down to the patch associated with security
    bulletin MS01-036. The output when attempting
    the password change on a domain controller that
    is running at Service Pack 3 is

    "00000005: SecErr: DSID-03190C3D, problem 4003 (INSUFF_ACCESS_RIGHTS), data
    0"

    We setup a test domain controller part of the same forest, running Service
    Pack 2 - unpatched,
    and are able to change passwords. The perl script which handles the
    password change performs the necessary delete and add operation per MS KB
    article 269190.

    Is anyone else successfully changing user's passwords via the LDAP interface
    and running
    Service Pack 3, or have other people run into this problem as well?

    Note the ability to "reset" a user's password is still functional, only
    password
    changes via LDAP seem to be broken.

    Thank You,

    -----
    Gabriel Kuri | Operating Systems & Network Analyst
    Instructional and Information Technology Division
    http://www.csupomona.edu/~iit | +1 909 979 6363
    California State Polytechnic University, Pomona

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo
    Have you discovered a security vulnerability related to Windows or a
    commercial product which runs on Windows?

    Need assistance crafting the format or translating your advisory to English?

    Need to verify it, or having problems contacting the Vendor?

    Contact mailto:Advisories@NTBugtraq.com

    oooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooo


  • Next message: http-equiv_at_excite.com: "SILLY BEHAVIOR Part II : Internet Explorer 5.5 - 6.0"

    Relevant Pages

    • Re: Virus in microsoft Patch
      ... "Windows must restart because the Remote Procedure Call ... your system and install the patch mentioned above. ... You can also configure Automatic Updates to automatically ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Difference between .NET and Java
      ... > people that I know agree with my speculation that the CLR was in fact ... > similarities between the CLR and the Win32 API. ... Actually what I ment to say was the .NET has Windows specific functionality ...
      (comp.lang.java.programmer)
    • Re: Is running a patch that changes something in Windows XP permis
      ... again for a Microsoft MVP: I have been trying to understand what the ... Windows XP versions before SP2 the system was recognised as SP2 RC1. ... > some things to quote here that tell us that the patch probably does not ... > change the value of TcpNumConnections in the registry and that there isn't ...
      (microsoft.public.windowsxp.general)
    • Re: Daylight Savings Time 2007 and Windows 2000 Server...
      ... Joe Richards Microsoft MVP Windows Server Directory Services ... support older versions of their software as well as Microsoft. ... patch for this problem but to also thoroughly test it and develop the ...
      (microsoft.public.windows.server.active_directory)
    • Re: CONFIG_VFAT_FS_DUALNAMES regressions
      ... The patch only changes the values stored for new files created by ... A filesystem is intact when all of its metadata is intact. ... in a virtual machine I connected it to the windows update service to ... see if there had been updates to the old install images I had, ...
      (Linux-Kernel)