Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How can someone access account names through the network?

Status
Not open for further replies.

PHead2

Technical User
Dec 18, 2001
222
0
0
I briefly had a friend's firewall down while we were trying to configure some things, in that short time many users tried to hack into the computer via the internet. Not only did they try various typical account names (Administrator, admin, sqladmin, etc.) but apparently they managed to get ahold of all the actual user names on the server to try (according to the security log).

How were they able to do this, aren't the user names encrypted?

Just curious...
 
hello,

tell me first the users are hack ur Server or accounts in through network or outside users from internet?

thanks
smudasir
 
Outside users from the internet...
 
you're allowing null sessions, and enumeration of SAM account names. You can play with RestrictAnonymous, but read this first:


RestrictAnonymous=1 may be your best bet if you only want to restrict enumeration of account names. You can do it through the registry, or through a security template.

John
MOSMENMTK
 
Are your email accounts named like the user accounts? i.e. username jsmith also has email account smith@company.com? Is your DNS secure? could a hacker use nslookup against it?
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top