Re: Server 2003 Administration Pack Security Flaw?

From: David Everett [MSFT] (deverett_at_online.microsoft.com)
Date: 08/20/04


Date: Fri, 20 Aug 2004 09:01:00 -0500

Hi Michael,

I'm not able to reproduce this with a test domain user account on my Windows
XP SP2 system using the W2K3 version of dsa.msc.

My test user account does not have the New option which prevents me from
creating any objects and I don't have right to delegate permissions either.

See if the domain user account can create a new top-level OU in the domain.
If this account can create OUs anywhere in the domain as well as user
accounts the view the Member Of tab on the properties of the domain user
account and get a list of all groups that this account belongs to. Then go
view the Member Of tab on each of those groups and check the membership of
the groups they belong to, etc... Perhaps this user account is nested in
the Domain Admin, Enterprise Admin, Administrators, or the Account Operators
group. Also, make sure someone did not place the Domain Users group into
one of the Administrative groups.

If the group membership appears to be correct, try viewing the Security tab
of the OU or domain head where the user created an object and see if Write
Permissions have been delegated to any of the groups that this user account
belongs to.

If you have the Windows Server 2003 Resource Kit installed on the XP machine
you can run "ifmember /list > groups.txt" and view the groups.txt file to
see if the domain user account is a member of any groups with elevated
rights.

NOTE: This can be downloaded from
http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&DisplayLang=en
and installed on the XP workstation.

-- 
David Everett
Microsoft Corporation
This posting is provided "AS IS" with no warranties, and confers no rights.
"Michael" <anonymous@discussions.microsoft.com> wrote in message
news:965901c48639$0d79cb00$a401280a@phx.gbl...
> I recently installed the Windows Server 2003
> Administration Pack on my XP SP2 machine and I came across
> something interesting...
>
> To avoid causing unnecessary damage to Active Directory, I
> created a regular user login for me to use on a daily
> basis and a Domain Admin account to use when I need to
> administer the AD.  On my local machine, I added my
> regular AD account to the (local) Administrators group so
> that I can install software, etc.
>
> After installing the Windows Server 2003 Administration
> Pack (again, with my regular domain account), I clicked on
> the "Manage Active Directory" icon on the Start Menu and I
> was able to not only see everything in AD, but I was also
> able to make changes in the AD.  (For example, I was able
> to disable a user's account.)  Thinking that for some
> reason the MMC had cached my domain login, I rebooted my
> machine and logged back in with my regular domain user
> account and it still let me make changes in the AD.
>
> My coworker even went as far as taking himself out of the
> local Administrators group on his machine and it still let
> him get into the AD and disable my account.  He then tried
> running AD Management as his local Administrator account
> and it said that he didn't have the proper permissions.
> But, as a regular domain user he is able to make changes.
>
> Since we have other "technology-related" departments in
> the building that have people that may know a thing or two
> about AD, I'm concerned that they may be able to get in
> and make changes.
>
> Has anyone else had this problem?


Relevant Pages

  • Win2K Server Security Hole ?
    ... My account is in the administrators group on our Domain. ... run Windows XP Pro, ... "Domain controller name is in domain domain. ...
    (microsoft.public.win2000.security)
  • Re: Remotely accessing WMI information without using a Local Administrator Account
    ... Some types of information are ONLY available to Administrators. ... First thing to do, is log the domain user directly into the Win2k3 box, and see if the WMI still says Access Denied. ... I have setup a domain user account and added this account to the ...
    (microsoft.public.win32.programmer.wmi)
  • Re: ADAM SP1 on Win2K3 SP1
    ... Assuming SSL on ADAM is working fine and i want to use antoher domain user account as the ADAM service account. ... Do i only need to grant that account READ permission to machine keys and use dsdbutil to change the ADAM service account? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Help XP Tricked me???
    ... > users (administrators) could not view my documents folder. ... > But now Eudora wont open on any other user account but mine.. ... Take Ownership of a File or Folder in Windows XP ...
    (microsoft.public.windowsxp.security_admin)
  • Re: How to set group policy
    ... that, this account is a local account, and I try to set ... Windows XP Security Console ... How to apply local policies to all users except administrators ... on Windows Server 2003 in a Workgroup Setting ...
    (microsoft.public.windowsxp.general)