Identifying domain admins from outside the domain?

Identifying domain admins from outside the domain?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Identifying domain admins from outside the domain? syrjalab 06-07-2005
Posted by on June 7, 2005, 7:22 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

We are having a problem on our WAN which is mystifying me.

Domain A (corporate headquarters) and Domain B (shop) are tied together
by a WAN, but the domains are not trusting each other. Occastionally a
trojan will infect a machine on Domain B which locks out all of the
accounts on Domain A that have domain admin rights, but none others.

We're going through the requisite security steps to make sure that this
doesn't happen again.

But my question is more specific: How can a machine on Domain B know
which accounts on domain A are domain administrators? No one has ever
logged on, mapped a drive, or done anything on the Domain B machines
which would give the trojan a clue as to which accounts to try.

Are Microsoft domains really so insecure that it's possible to not only
tell what accounts are domain admins, but what their specific names
are?

Regards,

Mystified



Posted by Leythos on June 7, 2005, 2:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
syrjalab@gsilumonics.com says...
> Hello,
>
> We are having a problem on our WAN which is mystifying me.
>
> Domain A (corporate headquarters) and Domain B (shop) are tied together
> by a WAN, but the domains are not trusting each other. Occastionally a
> trojan will infect a machine on Domain B which locks out all of the
> accounts on Domain A that have domain admin rights, but none others.
>
> We're going through the requisite security steps to make sure that this
> doesn't happen again.
>
> But my question is more specific: How can a machine on Domain B know
> which accounts on domain A are domain administrators? No one has ever
> logged on, mapped a drive, or done anything on the Domain B machines
> which would give the trojan a clue as to which accounts to try.
>
> Are Microsoft domains really so insecure that it's possible to not only
> tell what accounts are domain admins, but what their specific names
> are?

Any chance that you forgot to rename the administrator account?

Any chance that you have two accounts with the same user/password?

Any chance that you didn't patch the servers on both ends?

If you were to browse the network to the other server, can you reach
it's shares? Can you open them? So can a virus.

--
--
spam999free@rrohio.com
remove 999 in order to email me


Similar ThreadsPosted
5 Great .COM Domain Names Available NOW! January 30, 2005, 12:31 pm
Merry Xmas!! Domain name for you! December 25, 2005, 9:20 pm
List domain names May 3, 2006, 6:24 pm
What needs to be done to let a computer from a domain act as a Server out the web? July 26, 2006, 6:05 pm
Six Awesome .com Domain Names For Sale - NOW! February 14, 2005, 3:41 pm
Secure SSL certificate vs domain validated SSL? March 25, 2005, 7:56 am
how can I telnet a win2000 server in a different domain? April 19, 2006, 11:00 am
Why these ports are running on a W2K3 domain controllers? October 16, 2005, 7:33 pm
How is "0x43.0x9e.0x87.0xa9" a valid domain? May 19, 2006, 11:18 am
lart.com abuse domain owner is oretek.com's Joe Jared ("Taylor Jimenez") June 30, 2006, 9:02 am

The site map in XML format XML site map

Contact Us | Privacy Policy