Re: Disable %logonserver% browsing
- From: "Roger Abell [MVP]" <mvpNoSpam@xxxxxxx>
- Date: Tue, 29 Aug 2006 14:57:58 -0700
There are numerous ways to determine the DCs of a domain, particularly
if logged into that domain even as a limited user.
Trashing the environment variable that shows the DC that authenticated
the current login would adversely impact anything relying on that variable.
Just locating a DC was not your problem. Letting them have the ability
to define accounts, manage group memberships, was your mediate problem.
Just how they managed to do that, whether directly having logged in as an
account that was Domain Admins member in the forestroot domain, or
whether they exploited some unpatched vulnerability, etc. is what you do
need to determine. Until you can be sure of you immediate problem that
enabled the breach you cannot have confidence that you have prevented
it from being repeated. All the same, blocking one way of determining the
DC in use, is a relatively unimportant part of the fix, and preventing one
way for that to be done by a domain user is completely unimportant..
Roge
"Steve" <Steve@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:3AE29979-EB45-40FC-8F7F-6958EAA04448@xxxxxxxxxxxxxxxx
Hello,
I was wondering if there is a group policy setting that can be applied
that would prevent users from typing %logonserver% at the Internet
Explorer
adrress bar displaying the authenticating server? We had somebody
penetrate
our system and we believe that the person doing the hacking used this
method
to find a domain conroler, logged into it and then created an account and
put
it into the enterprise admins group. Is there a such policy that could
prevent this from happening in the future?
.
- Follow-Ups:
- Re: Disable %logonserver% browsing
- From: Steven L Umbach
- Re: Disable %logonserver% browsing
- Prev by Date: Re: Installing Applications via Group Policy
- Next by Date: Re: GP for no internet
- Previous by thread: Installing Applications via Group Policy
- Next by thread: Re: Disable %logonserver% browsing
- Index(es):
Relevant Pages
|