Re: users locked out spontaneously...

From: CRH (commanderdata@_NOT_myrealbox.com)
Date: 10/31/02


From: "CRH" <commanderdata@_NOT_myrealbox.com>
Date: Thu, 31 Oct 2002 01:03:17 -0600


> I run a small web hosting and presence provision company. Our servers are
> Windows 2000 (sp2) and we have separate servers running DNS, IIS (5),
> Exchange (5.5sp4), etc. The domain model basically has one "PDC" (or
> active directory equivalent) with the others getting the replicated
> security, AD, and DNS information.
>
> The problem is this: Twice now, I have had instances where not just one
> or two, but ALL users are for no apparent reason locked out of their
> accounts (Win2K).

Hmmm...........

> Is it possible that someone has hacked far enough to get the usernames of
> the accounts?

Yes.

> What is possibly happening? Are there any articles or security measures I
> might be missing?
>>> I have tried to take as much into account as possible, but these holes
>>> are discovered daily....

Make sure all your patches and anti-virus software is current.
Go here often http://www.microsoft.com/technet/security/default.asp.

Be wary if disgruntled employees esp. in IT.

--
Ciao,
CRH 8^)>


Relevant Pages

  • RE: Microsoft Active Directory security concerns
    ... for your DMZwith no trusts between it and your internal forest. ... limit the traffic from your DMZ web servers into the internal network. ... shuffling existing accounts into your new domain anyway. ... I have spent most of my time in network security and IDS/IPS technology ...
    (Security-Basics)
  • OE6 Passwords
    ... menu (Accounts> Properties> Servers), ... seems reasonable to be some kind of security thing but I've searched every ... If this is the wrong newsgroup, please tell me where to go. ...
    (microsoft.public.windowsxp.security_admin)
  • user right or security option
    ... I am working on a default security policy for company servers. ... templates is causing me problems. ... accounts for services, which access certain resources. ...
    (microsoft.public.win2000.security)
  • Re: Need urgent help regarding security
    ... There is plenty of security info out there ... email from even a dozen servers is small. ... an OS version upgrade should not be taken lightly. ... Given that your root password was apparently found on the servers, ...
    (freebsd-questions)
  • Re: Integrated security - why not?
    ... Let me explain why we seldom use Integrated Security for Internet asp.net ... how could we setup accounts for them? ... !server to the public network with services such as SQL Server (remember SQL ... The DC at the ISP is not for our own use. ...
    (microsoft.public.dotnet.framework.aspnet.security)