Possible inside security breach

From: G. Lentz (anonymous_at_discussions.microsoft.com)
Date: 08/28/04


Date: Sat, 28 Aug 2004 02:09:21 -0700

I have a strange situation that I really just need
clarification on so here goes.

I am an IT consultant for a company that has remote users
who connect via a VPN. One user, a recent contract
(potientially to be an employee) needed access to the
shared files/folders and e-mail. I gave him the
instruction on setting up the VPN on his home PC and was
going to get back to him on setting up the remaining
items (I work for other clients also) later. Instead of
waiting he and a friend logged onto the client's network
via the VPN and using their own words, "hacked and
guessed around about some things" so they could add his
PC to the domain and give him access to what he needed!
There are only two accounts on the domain that have
Administrator rights and his was neither. When I
questioned the user on this, suffice to say the friend
did all the work and he knows nothing. What really
puzzles me is that the client pricipal seems to think
nothing of this?!? He basically said well I guess you
have some competition.

Anyway my questions are:

1) I need to clarify that only an account with
Administrative privilages can create new user and
computer accounts in an AD domain?

2) Any possible ideas on how the hell they could have
done this? Don't need specifics, just could/can it be
done? I understand by the user having VPN access to the
network he basically had a key so to speak, allowing them
to bypass the normal things that discourage external
attacks (i.e firewalls).

I am going to try and speak to the client principla that
if they circumvented network security, then his network
is basically open at this point. Unfortunetely the
pricipal is high on this person and their abilities so I
may be creating an acrimonius situation by bringin it up.
My thinking is I don't want to be blamed for something
down the line as I feel I no longer have control over the
network. Thanks.



Relevant Pages

  • Re: Printer Problems: VPN? Backoffice? TS?
    ... I have a strange situation here, I'm not sure where the problem lies so ... this change was put in place a strange thing happened where the network ... uninstall the VPN client locally and reinstall a new one. ... doesn't recognize the trays. ...
    (microsoft.public.windows.terminal_services)
  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)
  • TidBITS#792/15-Aug-05
    ... We also note the release of Security Update 2005-007, ... Macintosh FTP client, free for educational and charitable use. ... mentioned virtual private network (VPN) technologies. ...
    (comp.sys.mac.digest)
  • RE: VPN Error 800
    ... The VPN client IP is 10.0.1.40, this is a private IP address. ... server IP address is 81.137.105.244, this is a Internet IP address. ... not test VPN connection from your perimeter network. ... SBS on your switch to make it work. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN with SBS 2003 (not R2) and DSL.
    ... Reading property value for VPN returned OK ... Reading VPN Server Name returned OK ... identical network cards. ... it seems doubtful that SBS will work properly with two NICs ...
    (microsoft.public.windows.server.sbs)