Renaming Administrator account

From: Derick Anderson (danderson_at_vikus.com)
Date: 11/15/05

  • Next message: Pidgorny, Slav: "RE: ISA Server or Firewall Appliance?"
    Date: Tue, 15 Nov 2005 16:21:23 -0500
    To: <focus-ms@securityfocus.com>
    
    

    A question for the list, inspired by the server hardening/break in
    threads:

    Is changing the Administrator account name really worthwhile or not? My
    largely unfounded, sparsely researched opinion is this:

    So far I haven't read a convincing argument for changing the name of the
    administrator account, and there's one reason I've chosen not to -
    account lockout policy. Only the domain Administrator account is exempt
    from lockout unless there's a special dispensation for Domain/Enterprise
    admins I don't know about. So choosing another account (and thus
    changing the SID) would take away the protection(?) against a DoS attack
    on the Administrator account.

    As for providing extra security, I believe it's security by obscurity.
    In order to access password-based systems, you have a set of public
    knowledge (username) and private knowledge (password): known * unknown =
    unknown, or in a (non)mathematical sense for brute force attacks, 1 * ?
    = ?. Now let's say you change the Administrator password, what have you
    gotten? Unknown * unknown = unknown, or ? * ? = ?. You've changed the
    equation but not the outcome. I realize that changing the name prevents
    automated attacks but can't this be defeated by not allowing direct
    remote Administrator access? (no VPN account, no OWA account, servers
    locked up in a datacenter...)

    Basically what I'm asking is whether changing the account name is a
    fundamental princple or just icing on the cake.

    Derick Anderson

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Pidgorny, Slav: "RE: ISA Server or Firewall Appliance?"

    Relevant Pages

    • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
      ... administrator account -- we should have no problems at least browsing to ... server. ... | authentication dialog box. ...
      (microsoft.public.inetserver.iis.security)
    • Re: Serious Security & Administrative issue!!!!
      ... capability [including file encryption and a boatload of security policies] to be ... The concept of the built in administrator account is ... if that account is only available in safe mode then hackers can not use it ...
      (microsoft.public.security)
    • RE: [VulnWatch] Blank Administrator password in DELL XP Professional install
      ... default out of the box configuration for any Windows XP Pro, ... this can lead to security ... risks if the administrator disables the account. ... Null Password on Administrator account. ...
      (VulnWatch)
    • Re: Update Error Code 800B0100 P.P.S.
      ... Here is the Direct link for that download for Vista x86 systems ... Administrator account that has full admin rights that could address those Windows updates that are not able to install. ... If the happens to be the built-in Administrator account, then enable it and set a password for it and login with the Administrator account. ...
      (microsoft.public.windows.vista.general)
    • RE: more info on a hopefully unsuccessful compromise
      ... Retina will still work ... accounts, btw, it's the Administrator account, and it belongs). ... has NO PASSWORD, it succeeds, and incorrectly logs the password as valid. ...
      (Incidents)

  • Quantcast