Click here to get back home

Normal user logging onto Win2003 Domain Controller?

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Normal user logging onto Win2003 Domain Controller? Zaheer Jassat 12-03-2007
Posted by Zaheer Jassat on December 3, 2007, 7:03 am
Please log in for more thread options
We have a Windows 2003 Domain Controller. Some time last week I found the
name of an 'ordinary' user in the C:\Document & Settings directory, which
seems to indicate that this user found a way to log onto the server. He also
has a user profile set up on the server (Roaming, which is what it normally
is).

I'm trying to work out how he managed to do this, and fix the security
breach so that no-one can do this again.

From what I can see, only "Administrators" can remote desktop into the
server, and the console session was locked with the administrator password
(which I am fairly certain he is unaware of). He is not listed as part of
the "administrators" group within Active Directory. I've tried to 'remote
desktop' in with the account in question, and I was denied access.

Does anyone have an idea as to how this might have been possible?

Thanks


Posted by Chris M on December 3, 2007, 7:25 am
Please log in for more thread options
Zaheer Jassat wrote:
> We have a Windows 2003 Domain Controller. Some time last week I found
> the name of an 'ordinary' user in the C:\Document & Settings directory,
> which seems to indicate that this user found a way to log onto the
> server. He also has a user profile set up on the server (Roaming, which
> is what it normally is).
>
> I'm trying to work out how he managed to do this, and fix the security
> breach so that no-one can do this again.
>
> From what I can see, only "Administrators" can remote desktop into the
> server, and the console session was locked with the administrator
> password (which I am fairly certain he is unaware of). He is not listed
> as part of the "administrators" group within Active Directory. I've
> tried to 'remote desktop' in with the account in question, and I was
> denied access.

That would cause me to be suspicious too...

Is the server just a DC or does it provide any other services?

--
Chris M.

Remove pants to email me.

Posted by Zaheer Jassat on December 3, 2007, 8:25 am
Please log in for more thread options
Its the DC, file & print server, runs SQL for a couple of (lightweight)
database applications. We also store userprofiles on this server. However
the server isn't a DHCP server.

In so far as Windows Services, its running what I assume Windows 2003
Service Pack 1 runs by default. Are there any specific services that I
should be looking out for?

> Zaheer Jassat wrote:
>> We have a Windows 2003 Domain Controller. Some time last week I found the
>> name of an 'ordinary' user in the C:\Document & Settings directory, which
>> seems to indicate that this user found a way to log onto the server. He
>> also has a user profile set up on the server (Roaming, which is what it
>> normally is).
>>
>> I'm trying to work out how he managed to do this, and fix the security
>> breach so that no-one can do this again.
>>
>> From what I can see, only "Administrators" can remote desktop into the
>> server, and the console session was locked with the administrator
>> password (which I am fairly certain he is unaware of). He is not listed
>> as part of the "administrators" group within Active Directory. I've
>> tried to 'remote desktop' in with the account in question, and I was
>> denied access.
>
> That would cause me to be suspicious too...
>
> Is the server just a DC or does it provide any other services?
>
> --
> Chris M.
>
> Remove pants to email me.


Posted by Chris M on December 3, 2007, 8:56 am
Please log in for more thread options
Zaheer Jassat wrote:
> Its the DC, file & print server, runs SQL for a couple of (lightweight)
> database applications. We also store userprofiles on this server.
> However the server isn't a DHCP server.
>
> In so far as Windows Services, its running what I assume Windows 2003
> Service Pack 1 runs by default. Are there any specific services that I
> should be looking out for?

I think first of all, I would have a look at the profile and see if you
can determine when it was created. Then you can have a look in the event
logs and see if anything out of the ordinary was happening during this
time. Look for lots of failure audits in the security logs, things like
that.

--
Chris.


>> Zaheer Jassat wrote:
>>> We have a Windows 2003 Domain Controller. Some time last week I found
>>> the name of an 'ordinary' user in the C:\Document & Settings
>>> directory, which seems to indicate that this user found a way to log
>>> onto the server. He also has a user profile set up on the server
>>> (Roaming, which is what it normally is).
>>>
>>> I'm trying to work out how he managed to do this, and fix the
>>> security breach so that no-one can do this again.
>>>
>>> From what I can see, only "Administrators" can remote desktop into
>>> the server, and the console session was locked with the administrator
>>> password (which I am fairly certain he is unaware of). He is not
>>> listed as part of the "administrators" group within Active
>>> Directory. I've tried to 'remote desktop' in with the account in
>>> question, and I was denied access.
>>
>> That would cause me to be suspicious too...
>>
>> Is the server just a DC or does it provide any other services?
>>
>> --
>> Chris M.
>>
>> Remove pants to email me.
>



--
Chris M.

Remove pants to email me.

Posted by Paul Adare on December 3, 2007, 9:03 am
Please log in for more thread options
On Mon, 3 Dec 2007 13:25:45 -0000, Zaheer Jassat wrote:

> Its the DC, file & print server, runs SQL for a couple of (lightweight)
> database applications. We also store userprofiles on this server. However
> the server isn't a DHCP server.

Check to see if the user in question has stored any EFS encrypted files on
the domain controller. That will cause a user profile to be created.

--
Paul Adare
MVP - Virtual Machines
http://www.identit.ca
Megahertz: A very large car rental company.

Similar ThreadsPosted
PKI User certificate auto-enrollment for XP clients not logging onto domain computer May 18, 2007, 11:02 am
How to Create Restricted User at the Win2K3 DOMAIN Controller August 14, 2007, 2:00 am
prevent user from logging on to servers March 31, 2006, 8:22 am
What is the difference between logging into an AD Domain versus connecting to network resource? January 26, 2006, 4:32 pm
Domain Controller That Service a DMZ October 29, 2005, 9:58 pm
Domain Controller Security January 13, 2006, 4:43 pm
Domain Controller Security Policy August 12, 2005, 4:31 pm
Want to make an Admin for only one Domain Controller April 7, 2006, 4:42 pm
Client and Domain controller across a firewall March 31, 2008, 5:32 am
2003 Domain Controller not requesting certificate May 31, 2006, 2:53 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap