Re: I think I may have found a security oversight.

From: Aaron H (aharrison@DONTBESPAMMINcsilaw.net)
Date: 10/17/02

  • Next message: CTO: "Security Policy - HIPPA Guidelines Template Format - 11"

    From: "Aaron H" <aharrison@DONTBESPAMMINcsilaw.net>
    Date: Thu, 17 Oct 2002 16:19:03 -0500
    
    

    Pete,
            Couple of things. One, when a computer is a member of the domain,
    and you have UserA on MachineA (member of the domain, Domain) When UserA
    access network resources, they're not accessing it as the local user on that
    computer, they're accessing it as Domain\UserA. Take a look at the *LOCAL*
    users. You may not even see a local user besides Admin, guest, etc. Now
    take NotebookA (which is not a domain member). On that notebook, it has
    UserA as a local account. When it's trying to access resources on the
    network server, SERVER, it tries to authenticate using the local notebook
    account UserA and password against the server's resources. If the user is
    in luck, there just happens to be a local user on the server with the same
    name and password. If either the local user name/password doesn't jive with
    the server's local username/passwords, you can't access the resources.

    Clear as mud??

    --
    Aaron H
    Austin, TX
    NT/Win2k IT professional
    fontouk at hotmail dot com
    

    "Pete Grazaitis" <pjgratz@yahoo.com> wrote in message news:20f7835.0210091114.a1080ed@posting.google.com... > Here is what I have found out. > > We run a mixed environment, native domain windows 2000 network. We > use group policies and scripts to control our connecting clients, > which are a mix of workstation's,servers's and laptop's. Since laptop > people are in and out of the office they tend to just log in locally. > This is fine except for the unfortunate ability to completely > circumvent our login scripts and group policies. However, they do > have the ability (provided using the same name and password) to get at > all of the shares on the network. It doesnt matter if the share has > all NTFS permissions based on the domain and the connecting client is > not part of the domain. This happens whether the NTFS permissions are > defined on the user, global group, or local group objects. Is this a > big problem, or am I overlooking something. > > The other thing I noticed was an XP client that thought one of the > login scripts was a potential virus and allowed the user to terminate > it. Anyway to lock that down too?



    Relevant Pages

    • Re: I think I may have found a security oversight.
      ... I would think for resources ... > and you have UserA on MachineA ... > network server, SERVER, it tries to authenticate using the local notebook ... >> circumvent our login scripts and group policies. ...
      (comp.os.ms-windows.nt.admin.security)
    • Re: Network with Win2K system & Guest username
      ... Because you're disabling the account that's being used for the sharing. ... On the WinXP PC, create local user account, with non-blank password, that have the desired access privileges to the desired shares. ... Log on to the other PCs using those account, and you will be able to access the designated shares, provided your network is configured properly. ...
      (microsoft.public.windowsxp.newusers)
    • Re: How to connect 2 workgroup PC
      ... On any XP Pro computer, check to see if Simple File Sharing (Control ... With XP Pro, if SFS is disabled, check the Local Security Policy ... look at "Network access: ... that the Guest account is enabled (for XP Pro, thru Local User Manager ...
      (microsoft.public.windowsxp.network_web)
    • [SLE] SLES9 YaST Fetchmail Problem - No User Accounts
      ... I'm trying to use YaST to configure fetchmail via the Incoming Mail ... In the "Local User" drop down, no local users are listed, only system ... "We manage your network so you can manage your business." ...
      (SuSE)
    • Re: XP File sharing gremlins
      ... >permission to use this network resource. ... On any XP Pro computer, check to see if Simple File Sharing (Control ... that the Guest account is enabled (for XP Pro, thru Local User Manager ...
      (microsoft.public.windowsxp.network_web)

    Loading