Re: Renaming Administrator account



"Jim Staunton" <sbsbofh@xxxxxxxxxxxxxx> wrote in message
news:qSKcf.249984$MS3.118925@xxxxxxxxxxxxxxxxxxxxxxxxx
>
>
> A remote attacker with no local account CAN'T authenticate to the domain
> controller, and so CAN'T determine a username from a well-known SID. She
> can, however, try to crack the administrator password by brute force. A
> dictionary attack - via attempted authenticated relay on your SMTP
> server? - could look like this:

Actually if restrictanonymous isn't set to 1 or 2 then unathenticated
queries are allowed. So, yes it CAN.

>
> U: administrator P: aardvark
> U: administrator P: aardwolf
> ...

....but presuming 2003 and no intential degradion of security, alls one has
to have is a user name infered from their email address and you have a
username. So go crack that password which likely is less secure than the
administrator one is. Now you've got an authenticated ability to lookup the
admin sid and targe it appropriatly. As I recall you can get the domain
password restrictions to aid your brute force. Commonly named accounts for
third party products are also a favorite target.

>
> This is going to take a hell of a lot longer than in the first scenario,
> so I would always recommend renaming the administrator account - and not
> to something simple like "admin" :-)

I'm not saying it doesn't help, just that securing AD isn't just one or two
items, it's a continuing process.

>
> Jim
>


.



Relevant Pages

  • Re: EFS on crashed OS
    ... when the client logs on (user account was ... Under the new instance of Windows, import the EFS certificate that should've ... They got a new SID in the new instance ... use the Administrator account to take ownership and then give ownership ...
    (microsoft.public.security)
  • Re: Process running under Adminstrator account
    ... I did not realize the SID was all that was needed. ... start with "administrator" and a dictionary or other attack? ... would not the changing of the admin name help? ... Renaming the account does not change the SID. ...
    (microsoft.public.windows.server.sbs)
  • Re: Process running under Adminstrator account
    ... It sounds as though the attack mentioned by Lanwench is an attack ... I did not realize the SID was all that was needed. ... Renaming the account does not change the SID. ... The Administrator SID ...
    (microsoft.public.windows.server.sbs)
  • Re: i want to change adminstrator user name
    ... > As the first responder already said, the administrator SID is still the same so ... >> processes and anything that will be disrupted by changing the Admin account. ...
    (microsoft.public.win2000.active_directory)
  • Re: no longer in the sudoers file..
    ... so just the administrator group.. ... i still can't install any application when i use that account to ... authenticate.. ... thomasg appserverusr admin appserveradm ...
    (comp.sys.mac.system)

Quantcast