Windows Security Hole in Symantec Ghost

From: Charlie (anonymous_at_discussions.microsoft.com)
Date: 05/27/04


Date: Wed, 26 May 2004 19:01:05 -0700

I recently started using the Symantec Ghost Console
(version 8) to remotely install software packages and
create inventories.
The way this is done is to add remote machines to the
Console. All of the machines that I have added are
Windows XP Pro on an NT4 Domain.
An account with Admin rights on the remote machines is
needed for adding them to the Console, which is what one
would expect, so I use the Domain Admin account.
The problem is that I can later log on to the Ghost
Console server with an account that DOESN'T have Admin
rights on the remote machines and install software.
I don't believe that I have ever seen an application that
behaves this way. I don't understand how it can connect
to remote machines based on the credentials of the user
who added them rather than the one who is logged on.
I'm hoping someone can explain this and maybe look into
it because it appears to bypass the usual access controls.
Thanks



Relevant Pages

  • Re: [opensuse] VNC on SLES 8
    ... Allowing remote logins via VNC. ... You can allow remote connection to the console. ... With this setup, you can connect to the actual console. ...
    (SuSE)
  • Re: [opensuse] VNC on SLES 8
    ... Allowing remote logins via VNC. ... You can allow remote connection to the console. ... want to use X on my PC, I need to VNC onto the server and work as if I ...
    (SuSE)
  • Re: Remote administration of a 2-node sun cluster running Solaris 5.8
    ... you trust to put a CD in the server. ... Some machine have RSC (Remote System Control) capability and others ... need to switch your console onto the RSC or ALOM controller. ... /etc/default/kbd and enable the alternate break sequence. ...
    (comp.unix.solaris)
  • Re: Remote Desktop Shadowing for Non-Adminsitrators
    ... Other option you have is to use Remote Assistance except it require someone ... on the console to accept the invite. ... >> To be able to logon to the console session you need the "logon locally"> right, which can be given in the local security policy or via GPO. ... >> I have setup TCP-RDP permissions to allow members of a domain group> Full ...
    (microsoft.public.windows.terminal_services)
  • Re: Cannot login as ordinary user to console session on Windows Server 2003 Standard SP1
    ... After connecting and entering correct user name and password I get the dialog box which says "To log on to this remote console session, you must have administrative permissions on this computer." ... RDP to the already logged on session, the connection succeeds. ... "Remote Desktop Users" group, and is not a member of "Administrators" group. ... Default Domain Security Policy / Security Settings / Local Policies / User Rights Assignment / Allow logon through terminal services. ...
    (microsoft.public.windows.server.general)