What's the purpose of "sid filtering disabled"
Windows Server Forum Index Windows Server
Server discussion on Windows platform.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web winserverhelp.com
What's the purpose of "sid filtering disabled"

 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory
Author Message
Spin
Guest





Posted: Mon Nov 14, 2005 1:50 am    Post subject: What's the purpose of "sid filtering disabled" Reply with quote

What's the purpose of "sid filtering disabled" I don't understand. I
actually don't even understand what "sid filtering" is. Please give me a
clue.

--
Spin
Back to top
Paul Bergson
Guest





Posted: Mon Nov 14, 2005 1:50 am    Post subject: Reply with quote

Sid filtering is used when there are trusts established. There is a way to
elevate privleges from one domain to another.

Once a trust is established there is an attribute available (SIDHistory)
that can be populated with sids from other domains. If you have some one
sniffing a remote network that finds an account that has admin privleges in
the remote network, they can populate there SIDHistory attribute with the
remote if they can change there own attribute.

To prevent this there is a Sid Filter technique that can block this.

Read about all of this at:
http://www.microsoft.com/windows2000/techinfo/administration/security/sidfilter.asp

--


Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA

This posting is provided "AS IS" with no warranties, and confers no rights.
Back to top
Spin
Guest





Posted: Mon Nov 14, 2005 9:50 am    Post subject: Reply with quote

Thanks for that Paul. You are indeed a gentleman and a scholar.

--
Spin
Back to top
 
Post new topic   Reply to topic    Windows Server Forum Index -> Active Directory All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




New Topics Powered by phpBB