Re: physical security

From: Ulf B. Simon-Weidner [MVP] (nospam2-ulf_at_usw-consulting.com)
Date: 10/23/04


Date: Sat, 23 Oct 2004 13:10:12 -0700


"Z" <z@hotmail.com> wrote in message
news:eWKHxGTuEHA.3016@TK2MSFTNGP12.phx.gbl:
> Hi All,
>
> Earlier I heard about that the offline Active Directory database attack is
>
> possible and some tool is availabel to this attack.
> I would like to read more about this attack surface. Can someone point me
> to
> the right direction?
> I think it is a real threat in a branch-office environment, where is the
> physical security insufficient.
>

Hello Z.,

You'd be able to hack any machine if you have offline access to it.
Only using Hardware HDD Encryption Technologies makes it much harder.

Any client you have will expose all it's local used accounts if a
hacker gets it (e.g. Service Accounts for Software Distribution which
runs under Domain Administrator rights,...), and a DC holds all
accounts of a company so it exposes all if it's hacked.

You do not even need to get into the database, you'd be able to hack a
DC which you have physical access and run a brute force attack against
all accounts.

-- 
Gruesse - Sincerely,
Ulf B. Simon-Weidner
  MVP-Book "Windows XP - Die Expertentipps":  http://tinyurl.com/44zcz
  Weblog: http://msmvps.org/UlfBSimonWeidner
  WebSite: http://www.windowsserverfaq.org


Relevant Pages

  • physical security
    ... Earlier I heard about that the offline Active Directory database attack is ... possible and some tool is availabel to this attack. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Protection from Hackers
    ... protect your hard drive from an intruder that had physical access to your ... protect the accounts in the domain from this sort of attack [though the ... Linux / Unix / BSD are also vulnerable to this sort of attack. ...
    (microsoft.public.win2000.security)
  • Re: ssh security
    ... what are valid accounts and what are not. ... It's considered axiomatic that security ... > system accounts (and over 99.9% are root, which does not get ssh access ... There are even some bots and apps that attack you from different IP ...
    (Fedora)
  • Re: Pubstro rash
    ... passwords against all of the accounts. ... We see this type of attack regularly in the .EDU world. ... administrator password on many machines, ... if there is a local administrative user named "brian" on that same ...
    (Incidents)
  • Re: TMNSP site attacked, back up
    ... > Due to an external attack, tmnsp.net has lost all users accounts ...
    (rec.music.gdead)