I think I may have found a security oversight.

From: Pete Grazaitis (pjgratz@yahoo.com)
Date: 10/09/02


From: pjgratz@yahoo.com (Pete Grazaitis)
Date: 9 Oct 2002 12:14:39 -0700

Here is what I have found out.

We run a mixed environment, native domain windows 2000 network. We
use group policies and scripts to control our connecting clients,
which are a mix of workstation's,servers's and laptop's. Since laptop
people are in and out of the office they tend to just log in locally.
This is fine except for the unfortunate ability to completely
circumvent our login scripts and group policies. However, they do
have the ability (provided using the same name and password) to get at
all of the shares on the network. It doesnt matter if the share has
all NTFS permissions based on the domain and the connecting client is
not part of the domain. This happens whether the NTFS permissions are
defined on the user, global group, or local group objects. Is this a
big problem, or am I overlooking something.

The other thing I noticed was an XP client that thought one of the
login scripts was a potential virus and allowed the user to terminate
it. Anyway to lock that down too?



Relevant Pages

  • Applying shutdown script by local GPO
    ... Group policies are applied from the domain ... controllers in the usual way. ... they are NOT on the network. ... I can't apply the scripts by GPOs from the domain controller because the ...
    (microsoft.public.win2000.group_policy)
  • Can I Disable Error Messages Produced by Software Restriction Policies?
    ... In a previous post I asked if there was a way to use Group Policies to ... prevent users' login scripts from running. ... brad dott berson att bytebrothers dott org ...
    (microsoft.public.win2000.group_policy)
  • Re: AD policy queries
    ... have you looked at the GPMC scripts? ... # Jorge de Almeida Pinto # MVP Windows Server - Directory Services ... BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx ... List the group policies and the OUs they affect. ...
    (microsoft.public.win2000.active_directory)
  • Re: Login Script
    ... If you're in a domain environment, you can specify a log on script through group policies. ... you'd have to be more precise about the type of animation you want to play. ... > create login scripts that cause certain animations to play upon startup. ...
    (microsoft.public.windows.mediacenter)
  • Securing trasmission
    ... on my group policies are trasmitted securely over the network? ... I want to make sure that the VB scripts I use cannot be intercepted by ... Prev by Date: ...
    (microsoft.public.windows.server.active_directory)