Win2k Suddenly Has Admin Password reset to blank

From: SM Casey (smcasey_at_flash.net)
Date: 08/27/03


Date: Wed, 27 Aug 2003 08:51:33 -0700


We have HW & SW Firewalls, latest Win2k & McAfee patches &
Virus DBs running. Local WS noticed that server
directories suddenly were not accessible to remote Admin
user. Reboot server and found all admin domain passwords
were somehow reset to blank. Have we been hacked? The
TCP HW & SW firewall logs do not show any unusual
activity. Virus scans do not reveal any unusual activity.

Physical premises security limits physical access to WS's
so there is no possibility of surreptitious use of any WS.

Seems that Win2k at some point in the last 4 hours just
reset the primary server/domain admin PW to blank. Has
anyone seen this before?

SMC



Relevant Pages

  • Re: Secure host newbie - fun - humm
    ... decision, as the admin, whether or not to take down the server. ... Listen, as a security specialist, I *know* that every single box that I, ... some level of risk and that there is no "100% I'm secure" level. ...
    (Security-Basics)
  • Re: Server Operator Role
    ... domain admin and then keep in mind that a domain admin can get Enterprise Admin ... Joe Richards Microsoft MVP Windows Server Directory Services ... The server operator role allows ... the group cannot run the TS Policy. ...
    (microsoft.public.win2000.active_directory)
  • Re: Two Server Setup Question.
    ... That external trust factor thing ... get your admin domain up first. ... Microsoft Certified Trainer, Microsoft MVP - Windows ... Microsoft Windows & SQL Server Advisory Panel Member ...
    (microsoft.public.windows.server.setup)
  • Re: Two Server Setup Question.
    ... That external trust factor ... get your admin domain up first. ... Microsoft Certified Trainer, Microsoft MVP - Windows ... Microsoft Windows & SQL Server Advisory Panel Member ...
    (microsoft.public.windows.server.setup)
  • Re: Two Server Setup Question.
    ... a student accessed lab and the school admin machines. ... separate routers and lan wiring so that the lab could be completely isolated ... not only from the admin lan but from the outside world. ... your old server be lab.school.org. ...
    (microsoft.public.windows.server.setup)

Quantcast