Curious Security Behavior

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: mjs (mjs_at_discussions.microsoft.com)
Date: 10/25/04


Date: Sun, 24 Oct 2004 17:01:04 -0700

I am curious about a remote access behavior that I find puzzling. Why is it
possible to remotely manage a computer (win2K) from a server (win2K3) without
authenticating to it as long as the users name and password on the server
"happen" to match a privileged one on the remote computer? This is true
(maybe only pertinent) when the remote machine is not in the server’s domain.
 When trying from a different PC (Win2K) also not in the domain to the target
PC there is at least an authentication challenge of user name and password.
Granted the likelihood is small of this happening but it does seem like
strange/risky behavior. --- Mike



Relevant Pages

  • SecurityFocus Microsoft Newsletter #152
    ... MICROSOFT VULNERABILITY SUMMARY ... Real Networks Helix Universal Server Remote Buffer Overflow ... ... NEW PRODUCTS FOR MICROSOFT PLATFORMS ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #140
    ... Cafelog b2 Remote File Include Vulnerability ... Webfroot Shoutbox Remote Command Execution Vulnerability ... Pablo Software Solutions Baby POP3 Server Multiple Connection... ... Microsoft Windows XP Nested Directory Denial of Service... ...
    (Focus-Microsoft)
  • Re: WSUS Deployment
    ... If there is the need for changing the server ip address and you are nmot allowed to configure it via domain gpo's, contact your higher level admin, that he should do the job for you. ... but a reasonable number of Win2K). ... me to see, and open, and modify a remote client's local group policy ...
    (microsoft.public.win2000.group_policy)
  • RE: SBS 2003 sudden services problem over router based vpn
    ... I understand that your remote cannot receive POP3 emails through VPN ... SBS Server through routers. ...
    (microsoft.public.windows.server.sbs)
  • RE: Download connection Manager through RWW
    ... the issue may occur due to the Remote VD is ... Then please rerun the CEICW wizard and Configure Remote access wizard ... Start Internet Explorer. ... Since the Symantec anti-virus application installed on the server, ...
    (microsoft.public.windows.server.sbs)