Solved

All Domain User Accounts Locked - Including Admin

Posted on 2004-08-11
10
407 Views
Last Modified: 2008-03-10
The title says it all...
Every account on the domain is locked out. I can not get in to unlock any of them.
This is a NT4.0 domain.

My primary concern is How do i get in so that i may unlock the accounts?

THis is urgent for me, so i am giving as many points as i can.

Thanks,
Hudson
0
Comment
Question by:hudsonbeck
  • 4
  • 3
  • 2
  • +1
10 Comments
 

Author Comment

by:hudsonbeck
Comment Utility
I have been unable to find much helpfu info on the net...

The Admin account is locked as well...

Immediate help is very much appreciated, I will try to increase points
0
 
LVL 9

Expert Comment

by:fixnix
Comment Utility
Since time is of the essence, I'll drop a quickie here then go look for details.  There exist small floppy-based linux distributions with a utility to blank or change any passwords on an NT based system.  I'll be googling for a specific url for you.  I carry such a floppy with me in my cd case for the times I am to fix a computer and the admin is on vacation or quit.
0
 
LVL 9

Expert Comment

by:fixnix
Comment Utility
well that was easy...this isn't the tool I used in particular, but it's one option.

http://www.petri.co.il/forgot_administrator_password.htm#1
0
 
LVL 9

Expert Comment

by:fixnix
Comment Utility
and http://home.eunet.no/~pnordahl/ntpasswd/bootdisk.html is the one I used on XP and 2k before.  Should work on NT as well according to the author of the program. Good luck!
0
 
LVL 20

Expert Comment

by:Debsyl99
Comment Utility
Hi,

Ok if I'm on the wrong lines here then I apologise as I'm win2k rather than NT - however - doesn't the account lockout policy have a fixed duration after which time you should be able to get back in? If I were you I'd consider isolating the network from external sources (or maybe even internal) as quickly as possible then proceed to examine whatever event/audit logs that you have in place to try find out what happened. It sounds possible that this is some sort of malicious attack, either way you obviously need to figure out exactly what's going on,

Deb :))

0
Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

 
LVL 20

Expert Comment

by:Debsyl99
Comment Utility
I'd maybe be tempted to review your lockout policy so that you can get back in more quickly until you can resolve this , malicious user activity or virus perhaps?

Deb :))
0
 
LVL 9

Accepted Solution

by:
fixnix earned 500 total points
Comment Utility
pull the cat-5, run the nix boot disks, get back in, and asess the situation (network cable still unplugged).  If you're compromised, you better reformat/reinstall, and don't restore executable files from backup media.  If you were r00t3d by someone good, you're done if you do.  If it was some other reason for getting locked out (human error or a stupid script kiddie pseudo-r00ting you w/ no backdoors), then you're in good shape simply booting the disks I mewntioned previously.....checking start/all programs/administrative tools/event logs/ or settings/control panel/event log/ once back in would definately be worthwhole tho.  If you enen have ONE hair stand up safing "this is an attack" you better follow Deb's advice and pull the ethernet plug before going farther.  If you've been r00ted you better plan on a reformat/reinstall.  If I r00ted your NT system, you wouldn't see *my* processes in task manager and I would be free to do whatever I wanted as user: SYSTEM..  Safe mode or not.
0
 

Author Comment

by:hudsonbeck
Comment Utility
I will try your sugestions asap. I really appreciate your help.
I'll let you know as soon as i get this figured out.

Any more info/suggestions are appreciated :)

Thanks
0
 

Author Comment

by:hudsonbeck
Comment Utility
Sry for the delay... got hit by a hurricane.

I was able to find our network admin account password and resolve the issue. one of the PC had an IRCBot that was hammering the administrative shares locking accounts out. we have resolved all issues.

Thanks soooo much for the help.

awarding points and again, Thank You!

Hudosn
0
 

Expert Comment

by:jelzein
Comment Utility
curiously, how did you track down the IRCBot?
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
If your business is like most, chances are you still need to maintain a fax infrastructure for your staff. It’s hard to believe that a communication technology that was thriving in the mid-80s could still be an essential part of your team’s modern I…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now