uh, oh (was:Re: w2k server compromised)

From: Dan Uscatu (duscatu@lunatech.ro)
Date: 01/29/03

  • Next message: Wilson, Kevin W. (WIL) : "RE: Bypass Traverse Checking?"
    From: "Dan Uscatu" <duscatu@lunatech.ro>
    To: <focus-ms@securityfocus.com>
    Date: Wed, 29 Jan 2003 18:03:37 +0200
    
    

    ok here are the conclusions:

     in order to create a second DC, one *must* set the DNS on this second
    computer to point to the first DC. dont ask why... my guess it has
    somehting to do with netbios names

     i have a DNS on linux on the network, it is resolving all computers
    including the first DC and the second one... but DCPROMO wont allow me
    to add the second DC for some obscure reason unless i set the DNS to
    point to the DC.

     anyway problem is solved, the server was reinstalled and all uid's are
    fine.

     but, what the hell:

     i am using my laptop outside the domain, logged in as local
    administrator.
    now i can access the c$ and d$ shares (and all others) on the DC without
    a password !!! can anyone guess why this thing is happening and what can
    i do to stop it ?

    p.s. the DC is not in internet so dont bother trying to get it :)



    Relevant Pages

    • Re: DNS on XP
      ... > to a DNS server somewhere. ... Win2000+ has a built-in dynamic registration capability but it is for the ... >> resolution since they wouldn't be able to find the DNS server after ... > still lost, dont bother to explain. ...
      (microsoft.public.windows.server.dns)
    • Re: DNS on XP
      ... > at the registrar and use your own DNS strictly to help your internal ... Will DNS keep track of changing ip on my pc ... > the difference between a DNS server and the clients.... ... still lost, dont bother to explain. ...
      (microsoft.public.windows.server.dns)
    • Issues migrating SBS 2003 domain to Server 2008 Standard
      ... We are stuck migrating our SBS 2003 domain to Server 2008. ... Fatal Error:DsGetDcName (SRV-EXCH) call failed, ... Verify your Domain Name Sysytem (DNS) is ... network connectivity to a domain controller. ...
      (microsoft.public.windows.server.sbs)
    • Re: AD management snap in cannot find DC (netdiag /v workstation)
      ... The name.local entries are used by my apache server to implement ... change button, more button, the "Primary DNS suffix of this ... Attr: subschemaSubentry ... Owner of the binding path: ...
      (microsoft.public.windows.server.active_directory)
    • Re: AD management snap in cannot find DC (netdiag /v workstation)
      ... button, more button, the "Primary DNS suffix of this computer", it should ... The Security System could not establish a secured connection with the server ... Attr: subschemaSubentry ... Owner of the binding path: ...
      (microsoft.public.windows.server.active_directory)