Re: Strange integrated authentication success



The two boxes have same passwords for Administrator and I logged on with the same passwords. But I don't think same password can be a free passport to the databases.

Windows allows remote authentication using local accounts. If the user name and password are the same on both boxes, the remote OS will let you in under the context of the remote account. I expect you'll see the same behavior if you access the file system, such as accessing the a remote administrative share (\\REMOTE_SERVER\C$).

SQL Server then allows you to connect because the local Administrator account is a member of the BUILTI\Administrators group.

--
Hope this helps.

Dan Guzman
SQL Server MVP

"Han" <hp4444@xxxxxxxxxxxxxxxx> wrote in message news:eVU9zveIHHA.5104@xxxxxxxxxxxxxxxxxxxxxxx
Hello

I am experiencing strange success of authentication.

I have two boxes, one xp-pro and another windows 2003, both have SQL2005.

Two boxes have no relationships except that they are in same network. Really nothing such as account and trusted relationship.

Expecting failure, I tried to connect from xp to win2003 with integrated authentication(trusted_connection=yes).

Result is success. I checked profiler and found the account name is recorded as Administrator.

What happened?

The two boxes have same passwords for Administrator and I logged on with the same passwords. But I don't think same password can be a free passport to the databases.

Do you have any idea?


.



Relevant Pages

  • Re: Performance monitor on a remote computer
    ... In the right pane of the subsequent two pane window, ... that is selected is "Local System Account". ... log counters on the remote machine. ... >> I am logged into both machines as an administrator. ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Administrator(s)
    ... Strong passwords are long, contain digits, special c ... locate any account that he has and disable it. ... child has knowledge of. ... > I have been the "administrator" since I installed XP ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Password questions/problems
    ... your server as the administrator to do something on the server. ... Here are some recommendations on your user account and passwords ... Reason: User MUST change passwords within 90 days. ...
    (microsoft.public.win2000.security)
  • RE: Mysterious "Support" account created on Win2k server
    ... Once a worm/trojan or an attacker successfully connect to a system via port ... Once a system is compromised with an administrator account, ... > for guessing admin ids and passwords. ...
    (Incidents)
  • Re: Firewall
    ... > a couple hours away in a remote office. ... > can log onto the comuputer locally is the administrator. ... > understand why no other account was created with more access than the ... If it is the built-in Windows SP2 firewall, ...
    (microsoft.public.windowsxp.security_admin)