Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Problem with account-lockouts if local-accounts are defined in a domain. |
|---|---|
| Date: | Tue, 04 Apr 2006 09:10:11 +0200 |
Thanx again if anyone can provide me a solution.
Mike
Hello,
Consider the following scenario:
Several workstations or servers that are domain-members contain a local useraccount (ie. testuser). In the domain also an account named testuser is defined.
In the above configuration I've experienced the following problem. While scanning some systems that are members of the domain, nessus tries to login to the local system using several combinations (username / no password, username / password=username). This results in two logons per enumerated account. However the scan also tries to login on the domain using the locally enumerated account. This means that for the testuser-account, scanning four domain-members results in eight invalid logins ==> result is that the domain-account is locked.
As far as I could see, the problem is related to the smb_login_as_users.nasl. This plugin tries to login using the locally enumerated accounts and uses the SMB/domain entry from the knowledge base. I did not define the SMB-domain in my nessusrc-file, however further investigation turns out that other plugins set the SMB/domain-entry, for example if NULL-sessions are enabled (true for my configuration), the smb_login.nasl sets the SMB/domain entry. According to my opinion, because of NULL-sessions being enabled, the smb_login_as_users.nasl now tries to authenticate local users against the domain.
Anyone else experienced this problem and if so, any advice on how this can be solved.
Thanx in advance.
Mike
_________________________________________________________________
FREE pop-up blocking with the new MSN Toolbar - get it now! http://toolbar.msn.click-url.com/go/onm00200415ave/direct/01/
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
_______________________________________________ Nessus mailing list Nessus@list.nessus.org http://mail.nessus.org/mailman/listinfo/nessus
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: nessus scan locally but it wont login with ssh, Opperstamper |
|---|---|
| Next by Date: | Re: nessus scan locally but it wont login with ssh, George A. Theall |
| Previous by Thread: | Problem with account-lockouts if local-accounts are defined in a domain., m g |
| Next by Thread: | Re: Problem with account-lockouts if local-accounts are defined in a domain., Nicolas Pouvesle |
| Indexes: | [Date] [Thread] [Top] [All Lists] |