Win2000 Security flaw?

  • Thread starter Thread starter regmaster
  • Start date Start date
R

regmaster

How is it possible that a user, with the same name and password, can log
into a domain were only his username and password exits?

What I've found:

A customer of us wanted to use Visio-Web via IE6. Usually Visio works with
the account from the one who's logged into the system. So in this case that
user did not exist in our AD cuz our customer is not allowed on our network.
When we created that user, with exact the same name and password, it worked.
This could mean that if I know a certain username/password and I create the
same account on my local domain I can log into that domain, as long as there
is a network connection possible.
This can't be true, or is it? And how do I get rid of this 'functionality'?

thanks.



Reg.
 
microsoft.public.win2000.security news group, regmaster
This can't be true, or is it? And how do I get rid of this 'functionality'?

This is by design, is the way the security subsystem works, it has
worked this way since NT 3.1 was released, and it is well documented.
 
Always been this way. I don't really see it as a security hole as they have
to have the username and password match so the account had to be created by
the admin. in both places.
 
Back
Top