Partial profiles appearing on W2K GC

Partial profiles appearing on W2K GC

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Partial profiles appearing on W2K GC Alan 07-03-2006
Posted by =?Utf-8?B?QWxhbg==?= on July 3, 2006, 10:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
A handful of partial profiles have appeared on a client's W2K GC in the
"documents and settings" directory.

The profiles belong to user accounts that are NOT administrator accounts.
The profiles only have three subdirectories instead of the customary twelve
subdirectories. The three directories are "Application Data", "Cookies" and
"Local Settings". NTUSER.DAT, ntuser.dat.log, and ntuser.ini are also created.

It is my understanding that user profiles should only appear on a W2K GC in
the "Documents and Settings" directory as a result of a user logging on from
the server keyboard, or by an administrator logging in via Terminal Services
(which is in admin mode).

Windows Update and the client's third party patch management software both
report the server as fully patched.

1) Is there any legitimate way that a non-admin user could create a profile
on the server?
2) If the profiles were created by a user using an exploit to elevate their
privileges via Terminal Services, how would you manually check to see that
the appropriate TS patches were actually fully installed?

Thank you

Similar ThreadsPosted
Partial Profiles Created on a file server September 29, 2006, 5:06 pm
How secure is partial md5 ??? April 5, 2007, 11:21 am
Login screen keeps appearing October 20, 2005, 2:49 am
strange log on username appearing April 7, 2008, 3:48 am
How to delete a warning message appearing after booting April 12, 2006, 12:11 pm
Custom Exit Module not appearing in Certificate Services snap-in November 8, 2005, 7:52 am
HELP!!! Roaming Profiles March 22, 2007, 11:35 am
Re: corrupted profiles and much more May 31, 2008, 6:48 pm
How to manage profiles??? October 3, 2008, 7:56 pm
Grant Access to Different Profiles February 12, 2008, 9:36 am

The site map in XML format XML site map

Contact Us | Privacy Policy