Click here to get back home

Re: Server 2008 Domains - Security issue

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Re: Server 2008 Domains - Security issue S. Pidgorny 02-15-2008
Posted by S. Pidgorny on February 15, 2008, 2:51 am
Please log in for more thread options
All valid points. I think .exe file substitution techniques existed for
pre-W2K8 systems. Anyway, if you have give full physical access to server -
you need to consider any outage a security event. Most organisations cannot
afford that. No organisation checks local admin passwords on domain
controllers.


--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Svyatoslav,
>
> Thanks for replying. I fully understand what you are saying. Best practice
> for us will to ALWAYS use bitlocker on every server.
>
> Just some things worth noting though. The existing 2003 "recovery"
> technique you pointed out is substantially more difficult to perform.
> Secondly, with the 2003 technique you cannot create secret accounts or
> elevate an account without leaving a tell. That being the reset of the
> Administrator's password. So the tell for a network admin is that he is
> not able to log on.
>
> The "modification" I have blogged is way easier to do and allows you to do
> things that could be very hard to spot. Access rights to OUs or computers
> etc.
>
> All the same, I think that the ability to launch a SYSTEM level process by
> an anonymouse user is bad form.
>
> Thanks for the feedback though.
>
> Dean
>


Similar ThreadsPosted
Windows 2008 CA can't issue to Windows 2003 server June 25, 2008, 11:53 am
Writing security rules for Server 2008 February 22, 2008, 9:36 pm
Any MS security options for single server 2008 x64 as notebook OS? January 17, 2008, 7:12 pm
The security of this directory server can be significantly enhanced - windows 2008 June 12, 2008, 7:32 pm
IIS or directory security issue on 2003 E server January 12, 2007, 9:56 pm
Bizarre File Security Issue in Win2003 server January 12, 2006, 9:50 am
Certificate server for disjointed domains. July 12, 2005, 10:38 am
Reposting my request Windows Server 2008 Contributor for book February 21, 2008, 3:46 pm
Security issue about NTUSER.MAN November 25, 2006, 12:45 pm
Security Issue/Question April 28, 2007, 12:12 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap