Default domain permissions on who can join a workstation to the domain

From: Constantino Tobio (ctobio_at_GMAIL.COM)
Date: 03/10/05

  • Next message: Tony Mason: "Re: Remote Windows Kernel Exploitation - Step Into the Ring 0"
    Date:         Thu, 10 Mar 2005 11:06:44 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Apologies if this was obvious to anyone but me, but I stumbled upon the
    following while researching a problem:

    http://tinyurl.com/6kdjh

    Apparently, the default behavior in a Windows 2000 and 2003 Active
    Directory is that any authenticated user has the ability to join
    computers to the domain up to 10 times. Upgrading your domain from NT
    4.0 to 2000 actually seems to open up a security attribute, rather than
    lock it down further. Why this isn't made a bit more obvious is beyond
    me. I've been doing this gig for 10 years (well, Win2k for 5 obviously)
    and I've never heard this mentioned anywhere, even among my peers and
    colleagues, or at the many conferences I've attended over the years.

    --
    NTBugtraq Editor's Note:
    Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
    --
    

  • Next message: Tony Mason: "Re: Remote Windows Kernel Exploitation - Step Into the Ring 0"

    Relevant Pages

    • Email Connectivity
      ... I am currently researching for my dissertation ... and would like to ask anyone for advice concerning email connectivity. ... I intend to build a database that amongst other things will record ... windows xp pro PC at home and a Windows 2000 pro PC at University. ...
      (comp.databases.oracle.misc)
    • Re: Spybot Error Message
      ... No apologies are necessary. ... MS-MVP Windows Shell/User ... > The PATH under Environment Variables was different ... >> %systemroot% is an environment variable that is the location of the ...
      (microsoft.public.windowsxp.general)
    • Re: Words gotten sluggish - Reinstall?
      ... If any apologies are due, ... using the internet. ... Opening a new word document from Windows Explorer's context menu: ... >> It looks to me like I should just reinstall Office 2003 and not waste ...
      (microsoft.public.office.misc)
    • Re: sfc /scannow Why XP NO - W2K yes
      ... I am guessing at the end of POSTING? ... guess i could be researching this myself ... but still don't comprehend someone's remark concerning "not using SFC command" unless it is a last resort. ... Microsoft MVP [Windows NT/2000 Operating Systems] ...
      (microsoft.public.win2000.general)
    • MS Paint and output resolution
      ... My apologies if the answer to my question is readily available on a FAQ ... and google groups. ... I'm using Windows 2000, but need to insure that this work on Windows 98 and ...
      (microsoft.public.win2000.general)