Re: Alerting deletion of SAM

From: Dmitry Korolyov (d__k_at_nospamformorons.mail.ru)
Date: 07/13/03


Date: Sun, 13 Jul 2003 04:25:40 +0400

Will do. Don't think that auditing will work, though - since deletion will happen when no auditing is in effect, and newly created SAM will have no auditing set in SACL...

-- 
Dmitry Korolyov
d__k@nospamformorons.mail.ru
To e-mail me, remove "nospamformorons" 
from the address.
  "Steven Umbach [MVP]" <n9rou@comcast.com> wrote in message news:eD1Qa.44276$GL4.11835@rwcrnsc53...
         Possibly if sam file has auditing enabled on it something will show up - not sure, or some other method to detect that creation date has changed . I will have to play around with that one. Let us know if you figure out a good way.  --- Steve
    "Dmitry Korolyov" <d__k@nospamformorons.mail.ru> wrote in message news:u$2y0oMSDHA.1552@TK2MSFTNGP10.phx.gbl...
    Thanks for reply, Steve.
    We are talking about a situation where sam deletion happens on a regular workstation (no services dependent on local accounts) while it is offline, using CIA commander disk or something like this. When system boots up and finds SAM missing, sure it could record this event somewhere, so I was wondering if there's a way to catch it and throw to centran management console (using MOM for example).
    -- 
    Dmitry Korolyov
    d__k@nospamformorons.mail.ru
    To e-mail me, remove "nospamformorons" 
    from the address.
      "Steven Umbach [MVP]" <n9rou@comcast.com> wrote in message news:Jm0Qa.47303$H17.14513@sccrnsc02...
             I do not believe that it will be recorded in Event Viewer - it can not be deleted/renamed while the operating system is running. It would become vary obvious when no one can access the computer since resetting the same deletes all non default accounts and groups. If any service relied on a created account to start, then it would fail and be recorded in the Event Viewer.   --- Steve
        "Dmitry Korolyov" <d__k@nospamformorons.mail.ru> wrote in message news:umpazUMSDHA.2852@tk2msftngp13.phx.gbl...
        We all know about deleting SAM database to reset local admin account. After reboot SAM gets rebuilt and local admin password is blank.
        So, is there a way to set the system to raise an alert (into event log, for example) when SAM database gets reset?
        -- 
        Dmitry Korolyov
        d__k@nospamformorons.mail.ru
        To e-mail me, remove "nospamformorons" 
        from the address.


Relevant Pages

  • Re: Alerting deletion of SAM
    ... I did check event log after deleting SAM. ... Do I need to have certain auditing to be set? ... Don't think that auditing will work, though - since deletion will ... > same deletes all non default accounts and groups. ...
    (microsoft.public.win2000.security)
  • RE: question regarding SAM file / l0phtcrack / pwdump2
    ... forces out auditing, password length, complexity, history, age, account ... question regarding SAM file / l0phtcrack / pwdump2 ... Check out Yahoo! ...
    (Focus-Microsoft)
  • Re: Alerting deletion of SAM
    ... Auditing will not work, since the OS to which the SAM applies, won't be ... same deletes all non default accounts and groups. ... After reboot SAM gets rebuilt and local admin password is blank. ...
    (microsoft.public.win2000.security)
  • Why doesnt HPUX 10.2 Auditing Work?
    ... I have setup auditing using SAM and told it to monitor sucess and failure ... permissions to access the file, tried to modify the permissions using ... When I go and view the logs using the SAM ...
    (comp.sys.hp.hpux)

Loading