Re: I think I may have found a security oversight.

From:
Date: 10/24/02


Date: Thu, 24 Oct 2002 08:12:31 -0500

In article <20f7835.0210210946.3bae0d10@posting.google.com>,
pjgratz@yahoo.com says...
> I
> think it is a problem with the design. I would think for resources
> associated with a domain part of the authentication should be in
> forcing the use of the domain in the authentication process. I dont
> know if that can be done, and Im sure a bright person can manipulate
> the token to include that. But, the average user who is lazy and
> decides not to log into the domain should not be able to circumvent
> the domains restrictions (ie policies).
>
>
Hello Pete!!!

You're right, that's what NT does, by design. What you need to do to
enforce domain security is set the login for the local machine with a
different id or password or both from the domain login. then they can
use their machines on the road, but they have to use your scripts,
policy if they want to see anything on the network.

Best regards,
Ed



Relevant Pages

  • RE: [fw-wiz] RDP and security
    ... administrators can choose to encrypt the data using a 56- ... a non-Windows authentication ... > Windows 2003 Server may fixed the issue. ... > design flaw that supposedly hasn't been fixed (ie. server ...
    (Firewall-Wizards)
  • Re: evaluate the best SSH client (was: Print in PuTTy)
    ... it has exactly nothing to do with protocol design. ... The only REQUIRED authentication 'method name' is public key ... It's very carefully phrased to omit any implementation details, ...
    (comp.security.ssh)
  • Re: Websites require a login
    ... The point of integrated security is to use the authentication ... The point of integrated security is to authenticate the user that *logs in*. ... on the local machine. ... That's why the server is requiring a login. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: [PHP] Is this the best way?
    ... but it's nice to do as much design and theory before the ... authenticated, and if they aren't, have it call the authentication ... // show login form or redirect to login page or show error ... have to be a straight variable type value. ...
    (php.general)
  • Re: Roaming profile in problem
    ... > The logonserver is the local machine if a DC cannot be found, ... > "Herb Martin" wrote in message ... > In no way does ping tell you this. ... > Ping FAILURE would make it unlikely that authentication ...
    (microsoft.public.win2000.active_directory)