Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Querying AD from the internet

Status
Not open for further replies.

GVN

MIS
Dec 2, 2005
238
0
0
US
Is it possible to query someone's internal Active Directory on their network from the internet? If so, how can you block it or lock it down from being "open"?

The reason that I ask is because we have been receiving spam on very new and obsure e-mail addresses that were just created. This got me wondering if a query or lookup were possible from an outside source. Are there any tools the exist to check ones config to see if you are exposed? Thanks.

GVN
 
I think it's more likely that you have always been receiving these e-mails, there was just never a mailbox with that e-mail address to receive them. We get thousands of junk messages every day, most of which are addressed to people that simply don't exist... yet.


Carlsberg don't run I.T departments, but if they did they'd probably be more fun.
 
But is it possible to query someone's internal Active Directory on their network from the internet? If so, I want to block it from being accessible, because their other other risks if it is besides just getting spam... Does AD just use LDAP to do it, or other ports as well?
 
You'd have to be domain-authenticated in order to query the directory. If that was the case, you'd have a lot more to worry about than spam e-mail. Really nothing to worry about; however, if you do still have concerns then how is your network gateway configured?

I assume (<-- a mistake I'm sure) that you've probably got a router/modem gateway configured to use NAT, with port forwarding to the severs hosting services? I assume you've not got the domain controllers on a DMZ or something. /wink


Carlsberg don't run I.T departments, but if they did they'd probably be more fun.
 
Yes, I just looked at the firewall and everything looks locked down. Everything is behind the firewall and port-forwarded, it's just me being paranoid I guess... Thanks!
 
It's always better to be safe, than sorry. Especially when it comes to security!


Carlsberg don't run I.T departments, but if they did they'd probably be more fun.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top