Cheers for that clarification. Time to script a password change!

2009/10/22 Ken Schaefer <[email protected]>

> Getting the domain admin NTLM hashes out of memory on the remote machine.
>
>
>
> You have to copy the tools across to the machine where the Domain Admin is
> logged into. That requires access to one of the Admin shares (usually
> workstations don’t have any other shares), and it would also involve running
> the tool as a local admin of that remote workstation. If all the local admin
> passwords are the same, then the local admin password you got from
> lophtcrack on your machine would be the same as the remote workstation
>
>
>
> Cheers
>
> Ken
>
>
>
> *From:* James Rankin [mailto:[email protected]]
> *Sent:* Thursday, 22 October 2009 8:05 PM
> *To:* NT System Admin Issues
> *Subject:* Re: Hmmm....anyone have any thoughts on this?
>
>
>
> I was thinking along the lines of the randomization of local admin
> passwords....luckily we only have about fifty actual workstations, the rest
> are thin clients. I'm not familiar with the tools used in the attack (apart
> from psexec) - can anyone explain to me which part of it requires that all
> the local admin passwords be the same (apologies if I am missing something
> painfully obvious)?
>
> Cheers,
>
> 2009/10/22 Ken Schaefer <[email protected]>
>
> ·         Secure physical access
>
> ·         Don’t allow people to boot alternate OSes
>
> ·         Do your workstations need to have $ shares enabled? Or available
> (e.g. block with firewall/router) **if** these are admin workstations
>
> ·         Randomize local Administrator passwords
>
> ·         Do not login locally to workstations with Domain Admin
> credentials. Login with normal credentials. Use other tools (e.g. RDP) with
> admin credentials to secured jump box or servers
>
> ·         Etc, etc
>
>
>
> Cheers
>
> Ken
>
>
>
>
>
> *From:* James Rankin [mailto:[email protected]]
> *Sent:* Thursday, 22 October 2009 7:56 PM
> *To:* NT System Admin Issues
> *Subject:* Hmmm....anyone have any thoughts on this?
>
>
>
> http://securitytube.net/How-to-own-a-Windows-Domain-video.aspx
>
> Or mitigating against it, specifically....although I am not sure how
> effective an attack this is. I would think blocking USB access and
> maintaining application whitelists would be my personal first step
>
>
>
>
>
>
>
>
>
>


-- 
"On two occasions...I have been asked, 'Pray, Mr Babbage, if you put into
the machine wrong figures, will the right answers come out?' I am not able
rightly to apprehend the kind of confusion of ideas that could provoke such
a question."

http://raythestray.blogspot.com

~ Finally, powerful endpoint security that ISN'T a resource hog! ~
~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/>  ~

Reply via email to