RE: Local Account Vs Domain Account

From: Matthew Wagenknecht (Matthew.Wagenknecht_at_quantum.com)
Date: 01/20/04

  • Next message: Michael Silk: "RE: Encrypt data - SQL Server 2000"
    To: "'Leon, Mauricio (Toronto)'" <Mauricio.Leon@WatsonWyatt.com>, focus-ms@securityfocus.com
    Date: Tue, 20 Jan 2004 12:30:47 -0700
    
    

    Passwords are stored in the registry for accounts that are used for
    services. You can easily pull them out locally on the machine with LSAdump,
    etc.

    If you use a domain account, anyone that compromises that host will have a
    domain account to play with. They would have access to all Everyone/Domain
    Users shares (which is a bad idea to allow anyway). Most companies allow
    dial-in and remote access (VPN, etc) for all domain accounts, which would
    give an attacker the ability to remotely access your LAN should they
    discover the dial-up phone number or VPN address. (Please, use two-factor
    auth on VPNS !!!!)

    If you use a local account with a password that is not used on any other
    host, the primary exposure would be local machine access; secondary exposure
    would be that the have an IP on your network. But if they are able to run
    LSADump locally, they already have that. They would have to work a little
    harder to get access to other systems based on domain credentials.

    As a side note, do not make the local account part of the Administrators
    group. This will make remote attacks more difficult.

    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Matt Wagenknecht CISSP | MCSE
    Sr. Security Administrator
    -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Never be afraid to try something new.
    Remember, amateurs built the ark; professionals built the Titanic.

    This email may contain confidential and privileged information for the sole
    use of the intended recipient. Any review or distribution by others is
    strictly prohibited. If you are not the intended recipient, please contact
    the sender and delete all copies of this email message.

    -----Original Message-----
    From: Leon, Mauricio (Toronto) [mailto:Mauricio.Leon@WatsonWyatt.com]
    Sent: Tuesday, January 20, 2004 8:00 AM
    To: focus-ms@securityfocus.com
    Subject: Local Account Vs Domain Account

    If you have to install a component or an application that runs using an
    account , what are the disadvantages/risks (from security standpoint)of
    using a Domain Account instead of a Local Account and vice versa.

    Mauricio

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Michael Silk: "RE: Encrypt data - SQL Server 2000"

    Relevant Pages

    • Re: Adding mac os tiger to sbs2k8
      ... The SBS console doesn't know what to do with the mac, ... So--I left it using the local account, ... So--in your case, if the domain account works well, I'd copy the desktop ...
      (microsoft.public.windows.server.sbs)
    • Re: laptops and local account access to offline files
      ... offline, but we know they need a local account to do so. ... If they log into their laptop using their domain account when they are off ...
      (microsoft.public.windows.server.active_directory)
    • Re: laptops and local account access to offline files
      ... offline, but we know they need a local account to do so. ... If they log into their laptop using their domain account when they are off ...
      (microsoft.public.windows.server.active_directory)
    • Re: "Edit Users..." Menu Item Disabled in Telephony Management Sna
      ... On the member server, make sure the domain account you are using to log on ... Running "tapicfg show" revealed that I had no Active Directory TAPI ...
      (microsoft.public.win32.programmer.tapi)
    • Re: Could not receive email, until user account was established
      ... Once I deleted that other person, and I entered our employees name into the user account, his mail worked right away. ... If they cannot login, they also don't get to run any applications, like Outlook. ... You mention that the user is loggin on under a domain account. ... Then you mention creating a local account by the same *username* as the one they use when logging in under the domain. ...
      (microsoft.public.outlook)