Go Back   Velocity Reviews > Newsgroups > MCSE
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

MCSE - Access to shares without logon to domain

 
Thread Tools Search this Thread
Old 02-15-2005, 02:17 PM   #1
Default Access to shares without logon to domain


Hello Everyone,

Domain Controller = Win2k3
Client = win2k3


When I logon to my client locally I can still access shared folders on my
Domain Controller through
Network Places. My question is this....

How secure is the logon to access shared folders on my Domain Controller
when I have not logged on to my domain? Can someone explain what is
happening during the logon phase.



Thanx again,

Damian




Damian
  Reply With Quote
Old 02-15-2005, 02:28 PM   #2
fygar
 
Posts: n/a
Default Re: Access to shares without logon to domain
On Tue, 15 Feb 2005 09:17:14 -0500, "Damian"
<damian@damian_damian.com> wrote:

>Hello Everyone,
>
>Domain Controller = Win2k3
>Client = win2k3
>
>
>When I logon to my client locally I can still access shared folders on my
>Domain Controller through
>Network Places. My question is this....
>
>How secure is the logon to access shared folders on my Domain Controller
>when I have not logged on to my domain? Can someone explain what is
>happening during the logon phase.
>


The user name and password that you are using on one machine exists on
the other. MS does you a favor and passes it through since they match
exactly.


>


....butch()


fygar
  Reply With Quote
Old 02-15-2005, 03:57 PM   #3
Neil
 
Posts: n/a
Default Re: Access to shares without logon to domain
did you hear "Damian" <damian@damian_damian.com> say in
news:aa2dnVtwc4Mino_fRVn-:

> Hello Everyone,
>
> Domain Controller = Win2k3
> Client = win2k3
>
>
> When I logon to my client locally I can still access shared folders on

my
> Domain Controller through
> Network Places. My question is this....
>
> How secure is the logon to access shared folders on my Domain

Controller
> when I have not logged on to my domain? Can someone explain what is
> happening during the logon phase.
>
>
>
> Thanx again,
>
> Damian
>
>
>


everyone group full control?

--
Neil MCNGP #30

- That which does not kill you...really hurts!


Neil
  Reply With Quote
Old 02-15-2005, 10:21 PM   #4
Damian
 
Posts: n/a
Default Re: Access to shares without logon to domain

"fygar" <> wrote in message
news:...
> On Tue, 15 Feb 2005 09:17:14 -0500, "Damian"
> <damian@damian_damian.com> wrote:
>
> >Hello Everyone,
> >
> >Domain Controller = Win2k3
> >Client = win2k3
> >
> >
> >When I logon to my client locally I can still access shared folders on my
> >Domain Controller through
> >Network Places. My question is this....
> >
> >How secure is the logon to access shared folders on my Domain Controller
> >when I have not logged on to my domain? Can someone explain what is
> >happening during the logon phase.
> >

>
> The user name and password that you are using on one machine exists on
> the other. MS does you a favor and passes it through since they match
> exactly.
>
>
> >

>
> ...butch()



I understand that it 'passes' the information along, but does it
use the same security process as longing onto a domain would provide?




Damian
  Reply With Quote
Old 02-16-2005, 02:49 AM   #5
Kurt
 
Posts: n/a
Default Re: Access to shares without logon to domain

You're not logging into the domain, you're passing credentials that match
known domain credentials along to a domain-member server (in your case the
DC, but could be any member-server or workstation). As far as share
permissions go - yes, you have the same permissions to the share as the
matching domain user account. This is just one of the many good reasons not
to allow users to use the same logon locally as they do for the domain.
"Everyone" refers to "All known accounts". Unknown accounts still have no
access even with "everyone - full control" selected.

That said, no domain logon ever took place, so the local user won't run a
logon script, be granted a session ticket or have any domain priveleges,
other than the specific ones granted for accessing shared resources (they
can access shares and print).

....kurt

"Damian" <damian@damian_damian.com> wrote in message
news:TsOdnSIPVd-u6I_fRVn-...
>
> "fygar" <> wrote in message
> news:...
> > On Tue, 15 Feb 2005 09:17:14 -0500, "Damian"
> > <damian@damian_damian.com> wrote:
> >
> > >Hello Everyone,
> > >
> > >Domain Controller = Win2k3
> > >Client = win2k3
> > >
> > >
> > >When I logon to my client locally I can still access shared folders on

my
> > >Domain Controller through
> > >Network Places. My question is this....
> > >
> > >How secure is the logon to access shared folders on my Domain

Controller
> > >when I have not logged on to my domain? Can someone explain what is
> > >happening during the logon phase.
> > >

> >
> > The user name and password that you are using on one machine exists on
> > the other. MS does you a favor and passes it through since they match
> > exactly.
> >
> >
> > >

> >
> > ...butch()

>
>
> I understand that it 'passes' the information along, but does it
> use the same security process as longing onto a domain would provide?
>
>





Kurt
  Reply With Quote
Old 02-19-2005, 03:27 AM   #6
MikeF
 
Posts: n/a
Default Re: Access to shares without logon to domain
this is a security hole that is a great asset when teaching acls classes
(renamed now but still the self-paced learning kits).
it's an easy hole to close if you pay attention when setting up accts.

Mike
Check register com for the truth about the onslaught of copulating robots.


"Damian" <damian@damian_damian.com> wrote in message
news:aa2dnVtwc4Mino_fRVn-...
> Hello Everyone,
>
> Domain Controller = Win2k3
> Client = win2k3
>
>
> When I logon to my client locally I can still access shared folders on my
> Domain Controller through
> Network Places. My question is this....
>
> How secure is the logon to access shared folders on my Domain Controller
> when I have not logged on to my domain? Can someone explain what is
> happening during the logon phase.
>
>
>
> Thanx again,
>
> Damian
>
>





MikeF
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
I cant access the MCP site T3M4N MCTS 1 03-18-2008 06:21 PM
Pix 515E Access ist issue ally0000 Hardware 0 01-12-2008 10:09 AM
Trouble joining a computer to a domain: network path not found daveh551 General Help Related Topics 1 08-11-2007 05:53 AM
Cannot access one URL Elke General Help Related Topics 1 12-02-2006 11:36 AM
USB Key not recognised on laptop in a domain, but is when logged in locally lawrend A+ Certification 4 04-24-2005 03:02 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46