ExamNotes.net  -  IT certification portal

ForumsCertResearchTop sitesNewslettersFree email
HomeRegister
Exams Notes
Practice exams
Exam games
Questions by email
Online training
Training videos
College degrees
Boot camps
Book store
Links directory
Tell a friend
For webmasters

CompTIA Exam Vouchers
Save money on CompTIA exams
Question of the day
Sign up to receive
interactive practice questions
for MCSE, CompTIA
Cisco and other exams
TestKing
Get MCSE, MCSD, CCNA, CCNP,A+, N+ and many more

* ExamSheets *
Guide for Success!
Actual Questions & Answers
MCSE, MCSD, A+ ,CCNA, CCNP
Oracle 8i, Oracle 9i

Online practice tests

Certification sites

Online university

Online college

Online education

Distance learning

Software forum

Server administration forum

Programming resources






This is interesting: Free IT Magazines | Databases help forum



Microsoft (MCSE, MCSD, MOUS, MCAD) > Server 2003 > Authentication

Show a Printable Version
Email This Page to Someone!
Receive updates to this thread






Author Authentication
isles1
Senior Member
M




Registered: Jan 2003
Location:
Country: United States
State:
Certifications: MCSA 2003, MCSA 2000, MCDST, MCP , CWNA, Security+, Network+, A+, B.S. MIS
Working on: CWSP, MCSE 2003

Total Posts: 349
Question Authentication

I cannot imagine why this would be intended, but is this normal behavior:

Users from an NT4 domain that also have accounts in a 2003 domain (right now only the IT dept as we are in the testing phase) can access servers in the 2003 domain from a PC while logged on to that PC with a NT4 account. The user IS NOT prompted for credentials before connecting to the server in the 2003 domain.

*Each user has the same username and password in the NT4 and 2003 Domain. As soon as the password is changed in one of the domains, the user IS prompted for credentials. Of course the domains have different names, so I am not even sure why the username is apparently being seen as the same in both domains. Isn't the username supposed to be seen as "NT4domain\%username%" and "2003domain\%username%"

There are NO established trusts.

Is this a known issue? This seems to be a security concern in a production environment.

Thanks in advance.

Report this post to a moderator

Old Post 02-26-04 07:25 PM
isles1 is offline Click Here to See the Profile for isles1 Click here to Send isles1 a Private Message Add isles1 to your buddy list Find more posts by isles1 Reply w/Quote Edit/Delete Message IP: Logged
jeff_j_black
that's what "THEY" said..




Registered: Jan 2002
Location:
Country: United States
State:
Certifications:
Working on:

Total Posts: 2723

You have experienced this first hand? What functional mode is the 2003 domain in? Never heard of this before. Without trusts, I don't see how it could happen.

Report this post to a moderator

Old Post 02-27-04 02:29 PM
jeff_j_black is offline Click Here to See the Profile for jeff_j_black Add jeff_j_black to your buddy list Find more posts by jeff_j_black Reply w/Quote Edit/Delete Message IP: Logged
isles1
Senior Member
M




Registered: Jan 2003
Location:
Country: United States
State:
Certifications: MCSA 2003, MCSA 2000, MCDST, MCP , CWNA, Security+, Network+, A+, B.S. MIS
Working on: CWSP, MCSE 2003

Total Posts: 349

quote:
Originally posted by jeff_j_black
You have experienced this first hand? What functional mode is the 2003 domain in? Never heard of this before. Without trusts, I don't see how it could happen.


Yes. I experienced it here at work after we set up AD yesterday. Current functional level is "Windows Server 2003."

Report this post to a moderator

Old Post 02-27-04 03:14 PM
isles1 is offline Click Here to See the Profile for isles1 Click here to Send isles1 a Private Message Add isles1 to your buddy list Find more posts by isles1 Reply w/Quote Edit/Delete Message IP: Logged
isles1
Senior Member
M




Registered: Jan 2003
Location:
Country: United States
State:
Certifications: MCSA 2003, MCSA 2000, MCDST, MCP , CWNA, Security+, Network+, A+, B.S. MIS
Working on: CWSP, MCSE 2003

Total Posts: 349

Well, this is the answer I got to my original question when asked in a TechNet webcast:

If the username and password is the same on both the NT4 and w2k3 domain, then they wont be promted for credentials. if you change the password in either domain but not both, then user will be prompted as the username and password being passed is no longer correct.

Report this post to a moderator

Old Post 02-27-04 07:17 PM
isles1 is offline Click Here to See the Profile for isles1 Click here to Send isles1 a Private Message Add isles1 to your buddy list Find more posts by isles1 Reply w/Quote Edit/Delete Message IP: Logged
KScheler
Senior Member




Registered: Oct 2001
Location: Abbott,TX
Country: United States
State:
Certifications: Network+, A+, MCSE NT4, MCSE 2000, MCSA 2000
Working on: MCSA/MCSE 2003

Total Posts: 734

I've seen this same thing with an XP machine making a connection to a W2k domain and also connecting to a W2k3 domain. I went to a seminar this week and Mark Minasi, the speaker, mentioned something about a little known service called net crawler that makes the computer browse and automatically make a connection to any other computer on the network if the logon and password are the same without any user authentication being done by the user. I agree, this could be scary.

Report this post to a moderator

Old Post 02-28-04 06:43 PM
KScheler is offline Click Here to See the Profile for KScheler Click here to Send KScheler a Private Message Visit KScheler's homepage! Add KScheler to your buddy list Find more posts by KScheler Reply w/Quote Edit/Delete Message IP: Logged
All times are GMT.
Post new thread   Post reply

Featured site: MCSE, MCSD, CompTIA, CCNA training videos



Forum Jump:
Rate This Thread:
Forum Rules:
Who Can Read The Forum? Any registered user or guest.
Who Can Post New Topics? Any registered user.
Who Can Post Replies? Any registered user.
Changes: Messages can be edited by their author.
Posts: HTML code is OFF. Smilies are ON. vB code is ON. [IMG] code is OFF.
 

ExamNotes forum archive


Powered by: vBulletin 2.2.8
Copyright ©2000, Jelsoft Enterprises Limited.

  Free Braindumps | mcse braindumps