Re: Running Login Script Problems

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Oli Restorick [MVP] (oli_at_mvps.org)
Date: 07/03/04


Date: Sat, 3 Jul 2004 12:41:14 +0100

Hi Matthew

You will need to place it on all domain controllers, as any domain
controller could be performing the login.

The trojan issue I was referring to is that others may plant some commands
on a workstation to run at login when a domain admin logs in to create
themselves a new domain admin account. It's trivially easy to do and
doesn't require anyone else to be on the network while you're logging in.
It depends on your environment as to whether you think this is a real risk.
If you're running a school or university network, then it's quite possible
that you'd be a victim of this sort of attack.

Oli

"MatthewL" <MatthewL@discussions.microsoft.com> wrote in message
news:BEA74A5B-17B4-4936-94E9-BAAFC8ADEA71@microsoft.com...
> The PDC is the only server that has the script on it. I have not placed
> it on the BDC.
>
> The special account I used is only when I run scripts. It is disabled as
> soon as I am done with the specific task in hand. I only use it when I am
> in the area and not for longer than I need it. I also make sure no one
> else is on the network when I perform these tasks.
>
> Thank you for your response.
> MatthewL
>
> "Oli Restorick [MVP]" wrote:
>
>> Have you replicated the login script to all your DCs' netlogon shares?
>>
>> If the "special account" is a domain admin account, you're asking for
>> someone to place a trojan on one of the PCs to gain domain admin rights.
>>
>> Oli
>>
>>
>>
>> "MatthewL" <MatthewL@discussions.microsoft.com> wrote in message
>> news:55FA0044-997F-47AF-AB36-72B7809BD2B7@microsoft.com...
>> > Our current setup is WINNT Server and 2000 Professional workstations.
>> > We
>> > have one domain on a single broadcast domain. All the computers
>> > include
>> > the same image from a network deployment. Every computer also has the
>> > exact same hardware configuration.
>> >
>> > This specific event will explain my question. I need to run a patch on
>> > all my computers (30) in a lab. On the PDC, I add a special account
>> > with
>> > admin rights and have it run a login script. I try to login all
>> > computers
>> > in the room with this new account and I get the following results: The
>> > first half of the computers login and run the script with no problems.
>> > The remaining computers in the room do not recognize the new account.
>> > After rebooting these computers, they will login but will not run the
>> > script. After rebooting another time, the script still does not run.
>> > All
>> > the computers include the same image from a network deployment. Every
>> > computer also has the exact same hardware configuration.
>> >
>> > I have been dealing with this issue for some time now and need to find
>> > a
>> > resolution to make things easier for me. Please let me know if you
>> > have
>> > seen this or know what needs to be done to change this.
>> >
>> > Thank you for your time.
>> >
>> > MatthewL
>> > Network Coordinator
>>
>>
>>



Relevant Pages

  • Re: Hacker activity?
    ... >login to a server, most as root but some are attempts to login to ... >telnet, all come from the same remote server, and all fail. ... >getting some odd cgi calls to a script on a secure ssl server. ... Make sure root cannot login to your system via ssh. ...
    (freebsd-questions)
  • Re: [opensuse] BASH: has $COLUMNS gone nuts?
    ... You do realize that lines & columns are dynamic values which at least some terminals and login daemons will continuously adjust right? ... What the above shows is that I dragged the corner of my PuTTY window (which was connected to sshd, not every terminal client nor every server daemon does this) making the window a little larger and without issuing any commands, and no possibility that any bashrc or inclusions got executed, the values changed, because the terminal told the daemon and the daemon told it's child processes. ... Try calling them from within a script: ... Although, I would also actually be perverse and say that since the SCO systems predate most others, including ALL linux, that you could actually make the argument that the dwindling remaining production sco boxes in the world are right and the 90 million linux & freebsd & sun boxes are all wrong. ...
    (SuSE)
  • Abusing poor programming techniques in webserver scripts V 1.0
    ... $login = Request.Form ... fool the database parser. ... verified in the script of access to the database, ... The SQL statement will be parsed by the database manager, ...
    (SecProg)
  • e107 remote commands execution
    ... Login bypass / remote code execution / cross site scripting ... "e107 is a content management system written in php and using the popular ... a script byrgod at <a href="http://rgod.altervista.org " ... //so, you see, we activate public uploads and .php extensions for attachments ...
    (Bugtraq)
  • Re: Limit desktop & start menu
    ... Create a login script that runs when users log into the TS, and map the R: ... persisitent "R" drive on the server itself and that may cure it. ...
    (microsoft.public.windows.terminal_services)