Re: uh, oh (was:Re: w2k server compromised)

From: Bronek Kozicki (brok@rubikon.pl)
Date: 01/30/03

  • Next message: Web Master: "Unknown Windows 2000 files?"
    From: "Bronek Kozicki" <brok@rubikon.pl>
    To: "Dan Uscatu" <duscatu@lunatech.ro>, <focus-ms@securityfocus.com>
    Date: Thu, 30 Jan 2003 16:35:42 +0100
    
    

    Dan Uscatu <duscatu@lunatech.ro> wrote:
    > i am using my laptop outside the domain, logged in as local
    > administrator. now i can access the c$ and d$ shares (and all others)

    1. you have the same password as your local administrator and as domain
    admin ; AND at the same time
    2. DC (and other computers in domain) is accepting NTLM (without
    Kerberos, ie. without "v2") authentication

    If you run AD in native mode, in most cases you can stop using NTLM auth
    and use NTLMv2 only. There is setting in GPO for that

    regards

    B.



    Relevant Pages

    • Re: Verification of replication
      ... >>> and even to corruption of the back end data file. ... >> thought was to ask the user for the cases then filter the forms to ... make sure that the users don't log on as an administrator. ... > laptop, and allow it to be administered only when connected to the ...
      (microsoft.public.access.replication)
    • Re: Problem with sharing a printer in VISTA
      ... Or right click Add Printer Run as administrator ... This Vista print subsystem is ... re-download the Vista drivers and try again? ... quad CPU running with 4GB of ram and my laptop is running duo CPU ...
      (microsoft.public.windows.vista.print_fax_scan)
    • Re: Default Shares
      ... I would not worry too much about disabling the default shares if they are ... administrator account to logon to any domain computer that is not known to ... local administrators group of domain computers which can be easily managed ...
      (microsoft.public.win2000.security)
    • Re: Pwdump3, LC4, SysKey & SAM with win2k passwords
      ... On laptop #1 I have administrator ... > rights, pwdump3 and Lopthcrack. ... > administrator rights. ... > anybody know if I can do a HEX dump of the SAM file and Xor the hashes ...
      (microsoft.public.win2000.security)
    • Re: Gaining Administrator Access to Windows XP Professional SP2 Sy
      ... "Shenan Stanley" wrote: ... me to gain Administrator access to my PC by blanking the ... what happens when your laptop is stolen and someone is ... Be sure you understand the encryption model you use (and how to ...
      (microsoft.public.windowsxp.security_admin)