Enquiry on a special scenario.

anonymous_at_discussions.microsoft.com
Date: 06/30/04


Date: Wed, 30 Jun 2004 03:35:16 -0700

Dear Sir/Madam,

I got an enquiry from my customer regarding security
setup. I am developing a system which accept single sign-
on. It means if the user can logon to the network and
have security level to touch different server. He/She can
use different systems, e.g. CRM, MIS .

The customer claims that there is a way to bypass the user
ID and password in the network in order to use all the
resource and systems in the network.

Someone can disconnect a PC physically from the network.
He/She created a domain and user ID in the PC, which same
as the domain and user ID in the network. Then, he/she
logon the domain and user ID in the PC. He/she can
connect the PC to the network again. Finally, he/she can
access all the resources in the network.
    
Best Regards,

Martin.



Relevant Pages

  • RE: Offer Remote Assistance - "Permission denied" - Windows XP SP2
    ... I am on a Novell network. ... > being made from and under the security context of a Local AND Domain ... > Allow logon through Terminal Services Administrators,Remote Desktop Users ... > Back up files and directories Administrators ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Help, Ive been hacked
    ... ID: 540 Source: Security ... > Event Type: Failure Audit ... > Event Category: Account Logon ... Your computer was not able to renew its address from the network ...
    (microsoft.public.windowsxp.security_admin)
  • Re: ATTN : Microsoft - Security Event 529....Second Request for help....
    ... According to the events, the logon ... failure is from the local machine account. ... disconnected from the network. ... Security Event ID 529 is a failure audit for logon/logoff. ...
    (microsoft.public.windows.server.sbs)
  • Re: No Shut Down or Restart for Domain Admins
    ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
    (microsoft.public.windows.server.active_directory)
  • SecurityFocus Microsoft Newsletter #50
    ... Subject: SecurityFocus Microsoft Newsletter #50 ... Specialist in Microsoft's Security Services Partner Program, ... Network Monitoring for Intrusion Detection ... Relevant URL: ...
    (Focus-Microsoft)