|
Roger makes an important point - shouldn't forget that
clients can "use" the DHCP server to hijack the DCs address simply by
registering the same name (MS DHCP servers will happily overwrite their own name
record in DNS, if configured to register client's names in DNS
!!!)
however, as this is a Win2k3 DC, you can aleviate this
security hole by running the DHCP service under a different security context
(instead of allowing it to register records using the machine's LSA account)
=> this way it won't be able to overwrite i's own and thus the DC's records
in DNS...
/Guido From: Roger Seielstad [mailto:[EMAIL PROTECTED] Sent: Dienstag, 10. Februar 2004 16:38 To: '[EMAIL PROTECTED]' Subject: RE: [ActiveDir] Changing DHCP Servers I'd
suggest against running DHCP on a domain controller, due to a know security
issue. However, its a fairly small window of opportunity, but it is a ugly hole
if it is exploited.
--------------------------------------------------------------
|
RE: [ActiveDir] Changing DHCP Servers
GRILLENMEIER,GUIDO (HP-Germany,ex1) Tue, 10 Feb 2004 09:49:42 -0800
Title: Message
- RE: [ActiveDir] Changing DHCP Servers Santhosh Sivarajan
- RE: [ActiveDir] Changing DHCP Servers Santhosh Sivarajan
- RE: [ActiveDir] Changing DHCP Servers Celone, Mike
- RE: [ActiveDir] Changing DHCP Ser... Santhosh Sivarajan
- RE: [ActiveDir] Changing DHCP Servers mathif
- RE: [ActiveDir] Changing DHCP Ser... rrutherford
- RE: [ActiveDir] Changing DHCP Servers Ken Cornetet
- RE: [ActiveDir] Changing DHCP Ser... Santhosh Sivarajan
- RE: [ActiveDir] Changing DHCP Servers Rich Milburn
- RE: [ActiveDir] Changing DHCP Servers Roger Seielstad
- RE: [ActiveDir] Changing DHCP Servers GRILLENMEIER,GUIDO (HP-Germany,ex1)
- RE: [ActiveDir] Changing DHCP Servers Frank Buechler
- RE: [ActiveDir] Changing DHCP Servers Arendt, Jordan LRN
- RE: [ActiveDir] Changing DHCP Servers Roger Seielstad
