RE: Renaming Administrator account

From: Depp, Dennis M. (deppdm_at_ornl.gov)
Date: 11/16/05

  • Next message: Thor (Hammer of God): "Re: RE: break in? - terminal services on alternate port"
    Date: Tue, 15 Nov 2005 22:01:30 -0500
    To: Derick Anderson <danderson@vikus.com>, focus-ms@securityfocus.com
    
    

    If you rename the domain administrator account, it is still the
    "administrator" account and is not subject to account lockout policies.
    This policy utilizes the administrator well known sid to determine the
    administrator account, not the name of the account. While it is
    security through obscurity, it will protect you against most worms that
    are in the wild that target the administrator account.

    Dennis

    -----Original Message-----
    From: Derick Anderson [mailto:danderson@vikus.com]
    Sent: Tuesday, November 15, 2005 4:21 PM
    To: focus-ms@securityfocus.com
    Subject: Renaming Administrator account

    A question for the list, inspired by the server hardening/break in
    threads:

    Is changing the Administrator account name really worthwhile or not? My
    largely unfounded, sparsely researched opinion is this:

    So far I haven't read a convincing argument for changing the name of the
    administrator account, and there's one reason I've chosen not to -
    account lockout policy. Only the domain Administrator account is exempt
    from lockout unless there's a special dispensation for Domain/Enterprise
    admins I don't know about. So choosing another account (and thus
    changing the SID) would take away the protection(?) against a DoS attack
    on the Administrator account.

    As for providing extra security, I believe it's security by obscurity.
    In order to access password-based systems, you have a set of public
    knowledge (username) and private knowledge (password): known * unknown =
    unknown, or in a (non)mathematical sense for brute force attacks, 1 * ?
    = ?. Now let's say you change the Administrator password, what have you
    gotten? Unknown * unknown = unknown, or ? * ? = ?. You've changed the
    equation but not the outcome. I realize that changing the name prevents
    automated attacks but can't this be defeated by not allowing direct
    remote Administrator access? (no VPN account, no OWA account, servers
    locked up in a datacenter...)

    Basically what I'm asking is whether changing the account name is a
    fundamental princple or just icing on the cake.

    Derick Anderson

    ------------------------------------------------------------------------

    ---
    ------------------------------------------------------------------------
    ---
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Thor (Hammer of God): "Re: RE: break in? - terminal services on alternate port"

    Relevant Pages

    • Re: Workstation Locked out!
      ... the domain Administrator account, ... Have you tried to log in with the local Administrator account using a blank ... When you go to the ctrl+alt+del login screen on the workstation and click ... I tried to connect an old XP pro box to the network using the connect ...
      (microsoft.public.windows.server.sbs)
    • Re: Rename administrator account policy affects domain admin user account
      ... You need to disable this policy on the default Domain Controller policy. ... As for why a Domain Administrator account is a local account for a DC. ... > I have created a GPO that renames the local administrator account on all ...
      (microsoft.public.win2000.group_policy)
    • Re: Run As Error
      ... this a local administrator account or a domain administrator account? ... the administrator have network access to this mapped drive? ... > error message occurs, stating an invalid path. ...
      (microsoft.public.windowsxp.general)
    • Re: URGENT - Restore directory services restore mode password
      ... > If you can login to the W2k DC with a domain administrator account, ... > to change the DS Restore Mode Administrator Account password on that DC. ...
      (microsoft.public.win2000.general)
    • Re: URGENT - Restore directory services restore mode password
      ... > If you can login to the W2k DC with a domain administrator account, ... > to change the DS Restore Mode Administrator Account password on that DC. ...
      (microsoft.public.win2000.applications)