RE: uh, oh (was:Re: w2k server compromised)

From: Thomas Cameron (ThomasC@mip.com)
Date: 01/29/03

  • Next message: Bronek Kozicki: "Re: uh, oh (was:Re: w2k server compromised)"
    From: Thomas Cameron <ThomasC@mip.com>
    To: focus-ms@securityfocus.com
    Date: Wed, 29 Jan 2003 14:29:29 -0600
    
    

    I imagine that the local administrator and the domain administrator's
    password are the same, and the laptop is passing the local account
    username/password pair to the server.

    Just a SWAG.

    Thomas Cameron, RHCE, CNE, MCSE, MCT
    Best Software - MIP

    -----Original Message-----
    From: Dan Uscatu [mailto:duscatu@lunatech.ro]
    Sent: Wednesday, January 29, 2003 10:04 AM
    To: focus-ms@securityfocus.com
    Subject: uh, oh (was:Re: w2k server compromised)

    ok here are the conclusions:

     in order to create a second DC, one *must* set the DNS on this second
    computer to point to the first DC. dont ask why... my guess it has somehting
    to do with netbios names

     i have a DNS on linux on the network, it is resolving all computers
    including the first DC and the second one... but DCPROMO wont allow me to
    add the second DC for some obscure reason unless i set the DNS to point to
    the DC.

     anyway problem is solved, the server was reinstalled and all uid's are
    fine.

     but, what the hell:

     i am using my laptop outside the domain, logged in as local administrator.
    now i can access the c$ and d$ shares (and all others) on the DC without a
    password !!! can anyone guess why this thing is happening and what can i do
    to stop it ?

    p.s. the DC is not in internet so dont bother trying to get it :)

    For the protection of our internal systems and those of our customers,
    MIP/Best Software blocks most email attachments. Please use plain text when
    corresponding via email with MIP/Best Software.



    Relevant Pages

    • Re: Domain Controllers Cant reach Default Gateway...
      ... Making the ISA a domain controller would ... DNS it was missing the CNAME entry with the GUID for the other ... DNS server doesn't support this feature. ... The problem is my XP Pro laptop. ...
      (microsoft.public.win2000.active_directory)
    • Re: Domain Controllers Cant reach Default Gateway...
      ... Making the ISA a domain controller would ... area of DNS it was missing the CNAME entry with the GUID ... DNS server doesn't support this feature. ... The problem is my XP Pro laptop. ...
      (microsoft.public.win2000.active_directory)
    • Re: Domain Controllers Cant reach Default Gateway...
      ... Making the ISA a domain controller would ... one of the domain controllers the active directory DNS zone ... DNS server doesn't support this feature. ... The problem is my XP Pro laptop. ...
      (microsoft.public.win2000.active_directory)
    • Re: Domain Controllers Cant reach Default Gateway...
      ... Making the ISA a domain controller would ... one of the domain controllers the active directory DNS zone ... DNS server doesn't support this feature. ... The problem is my XP Pro laptop. ...
      (microsoft.public.win2000.active_directory)
    • Re: Domain Controllers Cant reach Default Gateway...
      ... DNS it was missing the CNAME entry with the GUID for the other ... If a BIND server is being used, the design would be based on what ... One of them has Certificate ... Because the XP laptop wouldn't get the root certificate on it's own I ...
      (microsoft.public.win2000.active_directory)