Re: Strange integrated authentication success



No, I am using script, connecting from xp to win2003. Something like,

set con=createobject("adodb.connection")
con3="provider=SQLOLEDB; server=w3; Database=air; trusted_connection=yes;"

con.open con3
msgbox con.state

That's all. Result is success or 1. I think it should fail.

"Uri Dimant" <urid@xxxxxxxxxxx> wrote in message
news:Of0BMPfIHHA.1008@xxxxxxxxxxxxxxxxxxxxxxx
Han
You said that you log in xp server as administrator and open query
analyzer can connect to win2003 serer by using a xp login?



"Han" <hp4444@xxxxxxxxxxxxxxxx> wrote in message
news:e$fOgFfIHHA.3668@xxxxxxxxxxxxxxxxxxxxxxx
No xp's account is not a member of win2003's Administrator Group if I
understand your question properly.

Sure win2003's account of Administrator is a member of win2003's
Administrator Group or Builtin\Administrators.

"Uri Dimant" <urid@xxxxxxxxxxx> wrote in message
news:ODJIW0eIHHA.4848@xxxxxxxxxxxxxxxxxxxxxxx
Han
Is it possible that xp's account you connect to is a member of
Administrator Group on win2003 ?

"Han" <hp4444@xxxxxxxxxxxxxxxx> wrote in message
news:eVU9zveIHHA.5104@xxxxxxxxxxxxxxxxxxxxxxx
Hello

I am experiencing strange success of authentication.

I have two boxes, one xp-pro and another windows 2003, both have
SQL2005.

Two boxes have no relationships except that they are in same network.
Really nothing such as account and trusted relationship.

Expecting failure, I tried to connect from xp to win2003 with
integrated authentication(trusted_connection=yes).

Result is success. I checked profiler and found the account name is
recorded as Administrator.

What happened?

The two boxes have same passwords for Administrator and I logged on
with the same passwords. But I don't think same password can be a free
passport to the databases.

Do you have any idea?









.



Relevant Pages

  • Re: Administrator(s)
    ... Strong passwords are long, contain digits, special c ... locate any account that he has and disable it. ... child has knowledge of. ... > I have been the "administrator" since I installed XP ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Password questions/problems
    ... your server as the administrator to do something on the server. ... Here are some recommendations on your user account and passwords ... Reason: User MUST change passwords within 90 days. ...
    (microsoft.public.win2000.security)
  • RE: Mysterious "Support" account created on Win2k server
    ... Once a worm/trojan or an attacker successfully connect to a system via port ... Once a system is compromised with an administrator account, ... > for guessing admin ids and passwords. ...
    (Incidents)
  • Re: Securing workstations from IT guys
    ... use of the local administrator account and ... create a new account with local admin rights ... machines and the file server and you will have a basic access log with ... Advise HR guys to assign passwords to their excel/word files. ...
    (Security-Basics)
  • IE6 password autocomplete doesnt work as Administrator
    ... account "Administrator" the AutoComplete function of IE6 ... dialogs or forms containing passwords. ... want it to memorize these items and I click the "Yes" ... If I log onto a different user account, ...
    (microsoft.public.windowsxp.security_admin)