Re: admin shares and security
- From: "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx>
- Date: Thu, 2 Mar 2006 18:26:15 -0700
"Antti" <ab@xxxxx> wrote in message
news:%23Wa6ESfPGHA.648@xxxxxxxxxxxxxxxxxxxxxxx
"Roger Abell [MVP]" <mvpNoSpam@xxxxxxx> wrote in messageMakes sense.
news:Op70wsGPGHA.420@xxxxxxxxxxxxxxxxxxxxxxx
Some remote management tools use the admin shares.
If you are auditing login attempts you should be seeing logon
events of type 3 being recorded, success or failure, for the
network login attempts.
"Steven L Umbach" <n9rou@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:eu3lLVNPGHA.2796@xxxxxxxxxxxxxxxxxxxxxxx
If the lockout policy is configured on the computer that has the share or
if the computer is a domain computer and the domain policy has lockout
enabled then it should also apply to network logons. If you enforce
strong passwords then you can rethink using account lockout which can
lead to denial of service attack against uses. FYI if some user gains
administrator access then having administrator shares will be among the
least of your orries. --- Steve
You are both right. I tried to connect (with wrong password) to an admin
share of a server I was already connected to with another username. I
guess for this reason it didn't succeed and there was absolutely nothing
in security log. I tested another server's shares - and yes - I was able
to lock out the (server's local) admin account and events were logged.
Thanks.
Antti
If you start a new session to a server to which the login is
already connected the new session will use the existing
connection (and its credentials). Hence no failure.
If you attempt explicit mapping with use of different set
of credentials you should get a pop up saying you are
already connected to server with different credentials.
As it does not speak with server, no failure logged there.
.
- References:
- Re: admin shares and security
- From: Steven L Umbach
- Re: admin shares and security
- From: Antti
- Re: admin shares and security
- Prev by Date: Re: Getting Access is Denied
- Next by Date: Re: Services disabled by itself
- Previous by thread: Re: admin shares and security
- Next by thread: Re: Local authentication errors on Windows 2003 Server
- Index(es):
Relevant Pages
|