Re: Security Question

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



A simple ldap query will return the administrator account, but in Windows
2003 AD "anonymous" ldap queries aren't allowed. However, a logged in user
with no other special privileges can easily determine the name of the
Administrator account. While a typical user isn't going to know how to do
this (or care probably), spyware/malware or such could easily do this under
the user credentials. As Les said this "obscurity" measure isn't a
significant security layer for a determined intruder.

That said, I'm not aware of any spyware that has been found to do this, but
it is certainly possible.

--
/kj
"Les Connor [SBS Community Member - SBS MVP]" <les.connor@xxxxxxxxxxxx>
wrote in message news:%23hIktUOBHHA.3928@xxxxxxxxxxxxxxxxxxxxxxx
SMTP tar pit feature for Microsoft Windows Server 2003

http://support.microsoft.com/kb/842851

Getting a valid email address is one thing; the planets would have to be
aligned with the stars for someone to get a valid username from an AD
harvest, but if the email address is <name>@domain.com and the user
account is <name>, then it's a no brainer.

I see quite a few installs like this - I don't really like it but it's
because of defaults. Customizing user account and email address generation
is an obscurity measure, not effective against a black hat but keeps the
dabblers moving on.

--
Les Connor [SBS Community Member - SBS MVP]
-----------------------------------------------------------
SBS Rocks !
----------------------
"Tell me and I'll forget. Show me and I'll remember. Involve me and I'll
understand." - Confucius


"cjobes" <cjobes@xxxxxxxxxxxxx> wrote in message
news:uEgA%23KJBHHA.1196@xxxxxxxxxxxxxxxxxxxxxxx
Les,

Can you elaborate a bit more on this?

--
Claus
"Les Connor [SBS Community Member - SBS MVP]" <les.connor@xxxxxxxxxxxx>
wrote in message news:eMtbFTIBHHA.1220@xxxxxxxxxxxxxxxxxxxxxxx
From an AD harvest? If AD filter is on, this is one of the caveats -
hence the use of tarpitting for mitigation.

--
Les Connor [SBS Community Member - SBS MVP]
-----------------------------------------------------------
SBS Rocks !
----------------------
"Tell me and I'll forget. Show me and I'll remember. Involve me and I'll
understand." - Confucius


"cjobes" <cjobes@xxxxxxxxxxxxx> wrote in message
news:%23I2lDv0AHHA.144@xxxxxxxxxxxxxxxxxxxxxxx
Hi all,

A first for me, so I would like to get some feedback from other admins.

As a standard, we always change the Administrator account name to
something else. For the first time we had a breakin attempt at one of
our clients (SBS2003/ISA2004) that was using the correct renamed admin
account name. Now, the password is pretty complex but I still don't
like the fact that 50% of the safeguard is out there. Does anybody have
an idea how an outside hacker would be able to obtain that username?

--
Claus









.



Relevant Pages

  • Re: Errors After Changing Administrator Password
    ... > Thank you for posting to the SBS Newsgroup. ... to find it in DCOM_CONFIG though (this occurs on the SBS machine). ... How did you change the Domain Administrator account? ... I logged into the server, opened Server Management, selected the ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Question
    ... I keep a very tight monitoring and there is nothing from inside users that I ... renamed administrator account "from within". ... Les Connor [SBS Community Member - SBS MVP] ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Question
    ... Only the standard ports are open (SMTP,OWA,RWW and ... the renamed administrator account "from within". ... Les Connor [SBS Community Member - SBS MVP] ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Question
    ... Assuming SSL on OWA and RWW, but otherwise I've not heard of anything else ... the renamed administrator account "from within". ... Les Connor [SBS Community Member - SBS MVP] ... As a standard, we always change the Administrator account name to ...
    (microsoft.public.windows.server.sbs)
  • Re: Security Question
    ... Only the standard ports are open (SMTP,OWA,RWW and ... the renamed administrator account "from within". ... Les Connor [SBS Community Member - SBS MVP] ...
    (microsoft.public.windows.server.sbs)