Solved

changing the Administrator password

Posted on 2004-04-26
4
840 Views
Last Modified: 2013-12-04
I have observed that in a standard installation of XP(SP1) or Win2K(SP4) *any* user belonging to the "administrator"-group can change without any problm the password of the master-user "Administrator".
Is it possible to protect the password of the user "Administrator" against such changings?

nmm
0
Comment
Question by:nmm
4 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 150 total points
ID: 10923809
Not really... that's why there are best practices... but even with those being followed, it's still a trust issue. M$ Network Admin's face this when ever a new person joins their group, how long do you wait to give them full domain access? While you can't pevent it's changing, you may be able to log who changed it. The event log folder can also have pemissions set so that only "system" and "admin1" can delete the logs. That way there is accountability, but no real prevention. This is a something common to most OS's. The admin accounts are supposed to be the trusted accounts, if you are unsure, then you shouldn't give them access. There used to be a utility to lock the administrator account out, but M$ saw that this was the double-edged sword, and pulled it. The local administrator accounts can never be locked out, unless you could find that tool "admnlock
http://support.microsoft.com/default.aspx?scid=kb;en-us;q281140&sd=tech (still they can reset the password just as before, if they are admins)

If you tried to guess passwords using terminal services, you'd also Never Be Locked out, even if the failed attempts were exceeded- TS thinks of all accounts as Local, even if they are domain accounts. you will be disconnected from TS once you've guessed wrong a few times, but you can keep at it forever! But the user your trying to guess' passwrod would of had to log-on to that server first. Despite the patch for 2000, this still works on XPpro...
http://support.microsoft.com/default.aspx?scid=kb;EN-US;274372
-rich

0
 
LVL 41

Assisted Solution

by:graye
graye earned 50 total points
ID: 10924159
On the other hand... that means you can just have any one of those folks in the Administrators group run an application that puts the Admin password back to the way you want it.  We actually put a program like that in our login batch file periodically to clean up the mess the users make.

The program is called "RePass"... and is availabe as VB.Net source code at http://www.dpw.hood.army.mil/ftp/RePass
0
 

Author Comment

by:nmm
ID: 10926750
Thanks for that information!

If I am in the admin-group than it is possible to change the passwords of any other users in the admin-groupand than i am the only one, who can acess the system with admin-rights.
If I have admin-rights, so it should also possible to disable "repass".

And the idea to protect the log from changing will also not work: if I can change the password of admin1, than after doing that, I can login as admin1 and than I can erase the traces in any log i want.

What is the sense of "admnlock", if they
still "can reset the password just as before, if they are admins"?


-nmm
0
 
LVL 24

Expert Comment

by:SunBow
ID: 10929000
Admins can change passwords, it is their inherent right of control.

Admins as the most trusted of the tech staff, with all the keys at their disposal.

All admins must trust each othe, it is the nature of position, just as mgmt must trust them.

If one admin is not trusted by the others, it is past time for a reorg to change access rights to reflect trustability.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
File audit / tracking software 3 104
Thin secure Windows 10 5 102
Is my window10 Safe? after a malware removed by AV? 5 88
Risks of using Camtasia Studio 9 108
As I write this article, I am finishing cleanup from the Qakbot virus variant found in the wild on April 18, 2011.  It was a messy beast that had varying levels of infection, speculated as being dependent on how long it resided on the infected syste…
Many people tend to confuse the function of a virus with the one of adware, this misunderstanding of the basic of what each software is and how it operates causes users and organizations to take the wrong security measures that would protect them ag…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question