Re: more info on a hopefully unsuccessful compromise

From: Sergey Latkin (slatkin_at_phg.com)
Date: 07/14/03

  • Next message: Deus, Attonbitus: "RE: more info on a hopefully unsuccessful compromise"
    To: LiNERROR <linerror@stx.rr.com>, incidents@securityfocus.com
    Date: Mon, 14 Jul 2003 15:29:52 -0400
    
    

    LiNERROR

    Several questions

    What type of logon do you use - network, interactive? Is it a local or domain
    admin account? NT domain or AD?
    What events are generated in the security log when you are logging in whith
    those accounts?
    Do file sizes/timestamps/checksums of logon and security DLLs (like
    msgina.dll) are different among your Win2000proSP3 systems?

    On Monday July 14 2003 01:04, LiNERROR wrote:
    > yes i have, i just posted a little more information to better facilitate
    > the constant barrage of questions and answers, and to present an actual set
    > of questions that i am looking for answers to rather than continue with the
    > "your too stupid to now what your doing" answers that i have received.
    >
    > the difference between the accounts is almost none... 1 is the default
    > admin account with a strong password that shows up in the user manager. the
    > other three should not be there, and are not in the user manager, yet, you
    > can still access the system with the use of one of the three "ghost"
    > accounts.
    >
    > it's a little of setting to come in one day and find two systems on the
    > back waters of your network with the ability to be connected to with 3
    > passwords you never set.
    >
    > I tried to disable the default admin account in an attempt to perhaps lock
    > out the "ghost" accounts. however when i tried to i was presented with a
    > lovely message that the admin account can not be diabled.
    >
    > presently there are 4 sets of login/password that can login to the systems
    > admin with my password
    > admin with admin reversed
    > admin with admin and
    > admin with nothing...
    >
    > i am not aware of 2k having the ability to have one account with multiple
    > passwords... and if i am mistake how would i disable the other passwords.
    >
    > LiNE
    > ---
    >

    -- 
    Sergey Latkin
    Chief Technology Officer
    Pinnacle Health Group
    1-(800)-492-7771
    http://www.phg.com
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    

  • Next message: Deus, Attonbitus: "RE: more info on a hopefully unsuccessful compromise"

    Relevant Pages

    • Re: Oh Dear, Where to start?!
      ... > sort of security solution? ... > use, passwords, physical security, backup/disaster ... > admin, network admin, tech support, programming, and ... Theres lots of software out there for backups. ...
      (Security-Basics)
    • Re: inheriting a network
      ... Changed the passwords to the firewall and removed ... Any other golden nuggets of admin ... >> servers, a Virus scanner that was 2yrs out of date, the ... >> I would start by running the Microsoft Baseline Security ...
      (microsoft.public.win2000.security)
    • Re: Error message trying to download
      ... This posting is provided "AS IS" with no warranties, and confers no rights. ... I can not apply any updates on any machine in the domain. ... I also tried to log on as the local admin account - still ... I then logged on locally with a local admin account. ...
      (microsoft.public.windowsmedia)
    • Re: How can I change the admin password of all our XP PCs on the doma
      ... You don't go to each workstation and check if that user changed the local admin password. ... If the box has a problem that means you can't use a domain admin account to logon, it is usually quicker to rebuild than troubleshoot. ... If you want to control the Local Administrators on the workstations, just disable the Local Administrator, and then use another GPO or Script that adds a existing security group in your AD as member of the local Administrators on the workstations. ...
      (microsoft.public.windows.server.active_directory)
    • Re: Group Policy Editor
      ... don't want to let guests run in an admin account. ... If you mean *some* programs - group policy isn't where you do stuff ... Oh - and don't forget to complain to the product developers about ...
      (microsoft.public.windowsxp.security_admin)