I was thinking along the lines of the randomization of local admin passwords....luckily we only have about fifty actual workstations, the rest are thin clients. I'm not familiar with the tools used in the attack (apart from psexec) - can anyone explain to me which part of it requires that all the local admin passwords be the same (apologies if I am missing something painfully obvious)?
Cheers, 2009/10/22 Ken Schaefer <[email protected]> > · Secure physical access > > · Don’t allow people to boot alternate OSes > > · Do your workstations need to have $ shares enabled? Or available > (e.g. block with firewall/router) **if** these are admin workstations > > · Randomize local Administrator passwords > > · Do not login locally to workstations with Domain Admin > credentials. Login with normal credentials. Use other tools (e.g. RDP) with > admin credentials to secured jump box or servers > > · Etc, etc > > > > Cheers > > Ken > > > > > > *From:* James Rankin [mailto:[email protected]] > *Sent:* Thursday, 22 October 2009 7:56 PM > *To:* NT System Admin Issues > *Subject:* Hmmm....anyone have any thoughts on this? > > > > http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx > > Or mitigating against it, specifically....although I am not sure how > effective an attack this is. I would think blocking USB access and > maintaining application whitelists would be my personal first step. > > > > > > > > -- "On two occasions...I have been asked, 'Pray, Mr Babbage, if you put into the machine wrong figures, will the right answers come out?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question." http://raythestray.blogspot.com ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
