Cheers for that clarification. Time to script a password change! 2009/10/22 Ken Schaefer <[email protected]>
> Getting the domain admin NTLM hashes out of memory on the remote machine. > > > > You have to copy the tools across to the machine where the Domain Admin is > logged into. That requires access to one of the Admin shares (usually > workstations don’t have any other shares), and it would also involve running > the tool as a local admin of that remote workstation. If all the local admin > passwords are the same, then the local admin password you got from > lophtcrack on your machine would be the same as the remote workstation > > > > Cheers > > Ken > > > > *From:* James Rankin [mailto:[email protected]] > *Sent:* Thursday, 22 October 2009 8:05 PM > *To:* NT System Admin Issues > *Subject:* Re: Hmmm....anyone have any thoughts on this? > > > > I was thinking along the lines of the randomization of local admin > passwords....luckily we only have about fifty actual workstations, the rest > are thin clients. I'm not familiar with the tools used in the attack (apart > from psexec) - can anyone explain to me which part of it requires that all > the local admin passwords be the same (apologies if I am missing something > painfully obvious)? > > Cheers, > > 2009/10/22 Ken Schaefer <[email protected]> > > · Secure physical access > > · Don’t allow people to boot alternate OSes > > · Do your workstations need to have $ shares enabled? Or available > (e.g. block with firewall/router) **if** these are admin workstations > > · Randomize local Administrator passwords > > · Do not login locally to workstations with Domain Admin > credentials. Login with normal credentials. Use other tools (e.g. RDP) with > admin credentials to secured jump box or servers > > · Etc, etc > > > > Cheers > > Ken > > > > > > *From:* James Rankin [mailto:[email protected]] > *Sent:* Thursday, 22 October 2009 7:56 PM > *To:* NT System Admin Issues > *Subject:* Hmmm....anyone have any thoughts on this? > > > > http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx > > Or mitigating against it, specifically....although I am not sure how > effective an attack this is. I would think blocking USB access and > maintaining application whitelists would be my personal first step > > > > > > > > > > -- "On two occasions...I have been asked, 'Pray, Mr Babbage, if you put into the machine wrong figures, will the right answers come out?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question." http://raythestray.blogspot.com ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
