Re: Finding out admin username

From: BloodRed (bloodred71@earthlink.spamsucks.net)
Date: 10/13/02


From: "BloodRed" <bloodred71@earthlink.spamsucks.net>
Date: Sun, 13 Oct 2002 17:49:03 GMT


Be sure the setting Neo mentioned is set, and be sure the following is
configured in the Security Options on the servers:

Network access: Allow anonymous SID/Name translation - Disabled
Network access: Do not allow anonymous enumeration of SAM accounts - Enabled
Network access: Do not allow anonymous enumeration of SAM accounts and
shares - Enabled

The administrator account has a set SID no matter what you rename the
account to. If someone is able to translate the account names into the SIDs
associated with them, they'll be able to find the admin account very easily.
Then, it's just a matter of running a password crack against the account
since the local admin account can't be locked out.

-BR

"NeoSadist" <neos@dist> wrote in message
news:uqj6i62qpegbbd@corp.supernews.com...
>
> "SvS" <sevims@olisys.com> wrote in message
> news:u93Gt0ocCHA.1700@tkmsftngp10...
> > Guys, I've been maintaining couple of Windows 2000 Advanced Servers and
> > using terminal services to administer them. Since terminal service is
wide
> > open to internet, I decided to log the bad username/password attempts
to
> > it. One result really scared the hell out of me.. I'm using very unique
> > administrator username , (I changed the administrator account username )
> and
> > a very unique password to it.
> > I was going thru the logs today and noticed that somebody from outer
> > internet, knew my admin username!!!!.. From the logs I can only see the
> > usernames and the IP addresses of the user connecting from. I can't see
> what
> > password he tried, but he definitely knew my admin username which he
MUST
> > have extracted from somewhere.. There is absolutely no way, I mean NO
WAY
> he
> > could guess it...
> > Now, I'm curios if there is a bug in my server. All the security
patches
> > everything is upto date. But I guess this is not enough, Anybody have an
> > idea, how might be this happening ?
> > Thank you in advance,
> >
> > PS : Servers have netbios ports are opened but no anonymous access is
> > allowed. Shared to everyone however.
> >
> >
> >
>
> I'd say use a firewall, and also make sure ALL your machine's lan manager
> setup in the local security policy is set to NTLM replies only.
> Also, I'd say, if your entire network is win2k or above, including the
> server, just use tcp (no installed netbios protocol) but set it to use
> netbios over tcp.
> I'm not familiar with corporate networks, but I'd talk to symantec and/or
> read some stuff from www.sans.org 's reading room.
>
>
>



Relevant Pages

  • Re: Finding out admin username
    ... locate Network Access Policy under Security Options..or am I checking out ... I guess a small setting in the security policy makes it disables, ... > The administrator account has a set SID no matter what you rename the ...
    (microsoft.public.win2000.security)
  • Re: Distributing user-developed Linux software and licensing issues.
    ... Aside from server security, there is the ... application can be completely open source and secure ... account from a specific machine. ... Do open source web servers include the full source to ...
    (Fedora)
  • Re: How to run aspnet with system account
    ... Well, darn, Joseph. ... considering the "lack of security" ... Even if you only run your own code on your servers, ... >> Telling people that you CAN safely run ASP.Net under the System account ...
    (microsoft.public.dotnet.security)
  • Re: How to run aspnet with system account
    ... Well, darn, Joseph. ... considering the "lack of security" ... Even if you only run your own code on your servers, ... >> Telling people that you CAN safely run ASP.Net under the System account ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Have been hacked?
    ... Every service is a potential security threat, ... is certified and experianced to test your servers. ... change the name of the admin account and create ... log on the the server as an administrator... ...
    (microsoft.public.security)