Re: WINDOWS 2000 SECURITY HOLE

From: John John (audetweld_at_nbnet.nb.ca)
Date: 01/27/05


Date: Thu, 27 Jan 2005 08:29:13 -0400

Your Caps Lock key must have fallen in the security hole too.

John

IT_OPS wrote:
> I HAVE SEEN VERY BIG SECURITY HOLE IN MY NETWORK.I HAVE SINGLE WINDOWS DOMAIN
> AND DC IS ACTING AS FILE AND PRINT SERVER RUNNING ON SP4.ONE NORMAL USER
> WITHOUT ANY ADMIN RIGHTS FROM XP CAN ACCESS ALL THE SHARES AND COMPLTELY
> ADMINISTER DELETE FILES CAN SEE SECURITY LOG I MEAN HE CAN DO EVERYHTING.SAME
> USER IF HE GOES TO OTHER PC HE CAN NOT ACCESS ANYTHING MEANS IT IS
> NORMAL.AFTER THAT I UPDATE SERVER WITH ALL SECURITY PATCHES RELEASED AFTER
> SP4 AND CLIENT I PUT XP SP2 BUT STILL THAT USER WITH THAT PROFILE HE IS
> HAVING ADMIN RIGHTS.
> ONE MORE THING IF I DELETE HIS PROFILE THEN IF HE LOGS ON THEN EVERYTHING IS
> NORMAL.MEANS SOMETHING ON THAT PC WITH HIS PROFILE IF OTHERS LOG ON TO THE
> SAME PC IT IS NORMAL.
> MY MANAGEMET AFTER SEEING THIS WANTS REMOVE COMPLETELY WINDOWS OS FROM THE
> NETWORK.PLEASE CAN ANYBODY HELP ME WHY IT IS HAPPENED.