DSQuery on active directory

From: John Madden (chiwawa999_at_yahoo.com)
Date: 01/27/05

  • Next message: Edward VanDewars: "Users "bypassing" Group Policy restrictions"
    Date: Thu, 27 Jan 2005 06:43:42 -0800 (PST)
    To: focus-ms@securityfocus.com
    
    

    Windows 2000 and 2003 have added new functionalities,
    more precisely, DSQUERY and others like dsmod, dsget
    etc..

    I'm looking for a way to only allow administrators or
    a specific group (Helpdesk) to query the active
    directory.

    By default, a normal user can:

    - List all users with their username
    - List all the groups a user belongs to, this includes
    admin users
    - List all users who are disabled.
    - List all users that have been inactive for x amount
    of time
    - List all users with a password age greater then x
    - Etc...

    This to me should not be by default. If everyone was
    preoccupied by the "NULL SESSION" vulnerability a few
    years ago, then this should be right up there with it.

    Is there any way to limit who can query what ?

    Thank you

            
                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Mail - You care about security. So do we.
    http://promotions.yahoo.com/new_mail

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Edward VanDewars: "Users "bypassing" Group Policy restrictions"

    Relevant Pages

    • October 01, 2007 From "To Do" to "Done" in One Search
      ... That sums up Yahoo! ... Search experience that gets users the answers ... the real-time query suggestions we launched on Yahoo.com in July. ... Video, in addition to the link you get an inline ...
      (alt.internet.search-engines)
    • Re: Import External Date/Web query problem
      ... I like the WEB Query methos ... "Don Guillett" wrote: ... data from my Yahoo stock portfolio. ... MSN and also got the same results from a stock portfolio I set up there. ...
      (microsoft.public.excel)
    • Re: Import External Date/Web query problem
      ... Please feel free to goto the files section of xltrader yahoo group and look ... "Don Guillett" wrote: ... I have redone the query with the same results. ... MSN and also got the same results from a stock portfolio I set up ...
      (microsoft.public.excel)
    • Why do you suppose MS wouldnt...
      ... IIS setup to disallow search engine robots, so that a simple Google or Yahoo ... query for "Remote Web Workplace" or "Welcome to Windows Small Business ...
      (microsoft.public.windows.server.sbs)
    • Duplicates in Query
      ... I'm designing a query from two tables (Administrators and Budget) where I ... belong to multiple departments. ... Budget table duplicates to match each record from the Administrator's table. ...
      (microsoft.public.access.gettingstarted)