Re: Local System Account & Network Access



When you see a $ after the username that means it is a computer account so
apparently the computer account was able to authenticate and have access to
the share. You said that the share has only read for domain users group
which I believe would not normally contain domain computer accounts. I would
double check the membership of the domain users group, check the membership
of the computer account which you can do with the support tool gpresult, and
double check the share permissions to make sure it does not include users,
everyone, authenticate users, or any other group the computer is a member
of. As a test I would also try changing the share permissions to be a
specific domain user account or change the permissions to deny for domain
users to see what happens. --- Steve


"Alwin" <Alwin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:794D0F1E-0713-4317-9820-B4797C0043AD@xxxxxxxxxxxxxxxx
Thanks Steve, I enabled detailed logging on the server and redid the
excercise, these are the the only two entries from the event log:

User Logoff:
User Name: PCNAME$
Domain: MYDOMAIN
Logon ID: (0x0,0xBA816)
Logon Type: 3

and


Successful Network Logon:
User Name: PCNAME$
Domain: MYDOMAIN
Logon ID: (0x0,0xBA816)
Logon Type: 3
Logon Process: Kerberos
Authentication Package: Kerberos
Workstation Name:

Looks like it's connecting with some kind of 'system' computer account?

Just some background - I'm developing the service and the GUI that sends
the
commands to it. This seems to be more of a security issue than a
development
issue which is why I posted it here.
It's a real worry when programs work better than they are not supposed to
:-)


"Steven L Umbach" wrote:

Offhand I don't know exactly what is going on but what I would do is to
check the security log on the server that has the administrator share to
see
the type 3 logon event generated when access is allowed to the share and
the
user name. The events in the log are time stamped so it should be easy to
find. The info in the link below may also be helpful if you have not seen
it
yet on planning security for service accounts. --- Steve

http://www.microsoft.com/technet/security/topics/serversecurity/serviceaccount/sspgch03.mspx
-- The Services and Service Accounts Security Planning Guide


"Alwin" <Alwin@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:578755CB-FC31-4512-91D7-B8379710C22E@xxxxxxxxxxxxxxxx
Hi,

I have a custom developed windows service running on XP - very simple ,
it
accepts commands via TCP/IP and executes them on the pc on which it is
installed.

The service gets installed with 'Local System' account credentials
which
by
all accounts does not have access to network resources. I am however
able
to
send commands to the service instructing it to install software
packages
which reside on a network share (shared read-only for domain users) and
it
works just fine.

I am concerned because all the documentation I have read indicates that
this
should not be possible, are there any special circumstances where the
System
account can access UNC share paths?





.



Relevant Pages

  • Re: Random "computer account was not found" broken profiles Server
    ... It could be connectivity, DNS, computer account password, secure ... Speaking of connectivity, "ping" alone doesn't count. ... Make sure that your clients use only their local DNS Server. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Quick question on resetting computer accounts in AD
    ... SBS Server Management console does not have "Reset Account" command to ... In fact, the SBS Server Management console has already integrated ADUC, you ... Right click the computer account in right pane, ...
    (microsoft.public.windows.server.sbs)
  • Re: Changed name of machine = cant login
    ... I was getting an error "The credentials supplied conflict with an existing ... network cable, rebooted, logged in w/ local admin account, clicked my way ... creating a computer account in AD is not going to resolve your ... > The steps you took to rename the machine are wrong. ...
    (microsoft.public.win2000.networking)
  • Re: Local System Account & Network Access
    ... 'MyPc$' computer account when it is running as Local System. ... Logon ID: ...
    (microsoft.public.security)
  • RE: XP computers in W2K domain
    ... to the Domain and the Domain users then logon to any PC that is a Domain ... local Administrors group of each PC. ... Enter the Domain name the use a Domain Administrtor account to add the PC to ... Logon to the Domain not the local PC. ...
    (microsoft.public.windowsxp.general)