RE: windows domain question

From: Damien Adams (dadams@scientech.com)
Date: 04/19/02


From: "Damien Adams" <dadams@scientech.com>
To: <bejon@supertel.com>, "'Mike Coppins'" <mike@legolas.com>, <focus-ms@securityfocus.com>
Date: Fri, 19 Apr 2002 12:22:49 -0400

Actually this feature in Windows 2000 can be disabled. And once the machine
is removed as in the machine is no longer part of that domain I would
believe that this cached account information would be removed.

To remove password caching check out this e-mail, part of a previous thread
entitled "Password Caching"
http://online.securityfocus.com/archive/88/199760

Damien

>-----Original Message-----
>From: Bejon Parsinia [mailto:bejon@supertel.com]
>Sent: Friday, April 19, 2002 12:53 AM
>To: 'Mike Coppins'; focus-ms@securityfocus.com
>Subject: RE: windows domain question
>
>
>Mike,
>
>Speaking from experience, depending on the policies in place on
>the network,
>the laptop very well could retain sensitive information about the domain.
>My example is as follows, I take my laptop home with me every night. It is
>running Win2k Pro. I can leave my login information exactly the same as
>when I have it plugged into my domain at the office when I login to the
>laptop at home without any sort of VPN or public access to my network.
>
>What does this mean? The laptop contains cached information (username,
>password, domain name) that does not necessarily expire. I am just logging
>in to use my laptop at home without connecting to any resources other than
>my internet connection at the house. Dangerous, you bet. You can run
>utilities to capture and recover those passwords very easily. No need to
>disconnect it from the domain whatsoever.
>
>Hope this helps,
>
>Bejon
>
>-----Original Message-----
>From: Mike Coppins [mailto:mike@legolas.com]
>Sent: Thursday, April 18, 2002 9:46 AM
>To: focus-ms@securityfocus.com
>Subject: windows domain question
>
>
>If you connect a machine to a Windows domain, so things like SIDs change,
>machine IDs synchronised, etc, and then disconnected, what happens exactly?
>Does the node that gets disconnected generate a new machine SID or does
>information get left behind on the node?
>
>Putting the question into a scenario might help :) If a laptop (NT4 or
>Win2k) is connected to a domain, then is removed from the domain (as in, an
>admin goes into network properties and tells the machine that it is part of
>a bog standard workgroup again, is the laptop going to retain any
>information that it belonged to a domain before, and possibly security
>sensitive information about the domain?
>
>
>
>--
>Mike Coppins
>mike@legolas.com
>http://www.legolas.com/
>Currently looking for work: http://www.legolas.com/mikes/cv.html
>
>
>



Relevant Pages

  • dialup disconnect window problem
    ... Working on a new DELL laptop with Windows XP Media Edition. ... I have set the Internet Explorer options to "disconnect when no longer needed" and the disconnect ... The laptop does have a built-in wireless NIC, but the customer does not want it disabled as he want ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: multiple windows opening
    ... After uninstalling, one must download/run a removal tool to rid the machines of the "leftovers" and then reboot, preferably *before* installing another anti-virus application or security suite (e.g., OneCare). ... run Windows Update manually to make sure the machine's fully patched. ... Windows Firewall and Defender on its own. ... I have had windows live one care from the first setup of this laptop. ...
    (microsoft.public.security)
  • Re: another Windows nightmare
    ... after i hook this hdd up to the other laptop, will i be able to see contents ... of the windows directory. ... is that just because of the boot issue? ... You will need a computer with two cd drives, one of which is a cd/dvd-rw ...
    (microsoft.public.windowsxp.general)
  • Re: computer question
    ... The orchid programs are written for the Windows operating system. ... Judging software only runs under Windows XP ... Obtain 'bootcamp' from Apple and have the laptop run XP natively. ... Optimized virtualization is where you've memorized important phrases like ...
    (rec.gardens.orchids)
  • Re: multiple windows opening
    ... would not send me a laptop w/o it, ... I open it, it shows that the firewall is on, the virus thing is ... Windows defender is also off. ... When I had XP and windows one care, I remember that I was told to ...
    (microsoft.public.security)