Great Circle Associates Firewalls
(October 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: NT Security Descriptors
From: "Robert Carbone" <robc @ webster . imsi . com>
Date: Mon, 7 Oct 1996 10:17:39 -0400
To: firewalls @ GreatCircle . COM

If some one could help me out for a sec.
I was looking in the registry under security ( I have LOGON/LOGOFF 
security enabled) and when the machine comes up I get a user ANONYMOUS
going into the machine . I believe this is the token passing algorithm 
for the SID being sent to WinLOGON, though I could definately be wrong.

Also I get some Processes on the LOGON which are:
	
	1. NTLanMan- I am not sure?
	2. KsecDD - Is this the Network DDE stuff ??
	3. User32 - the LOGON verification Process?

I am running NT 3.51 service Pack 4.

I wanted to run Socks for NT on this machine , but until I understand 
the processes that run on NT for LOGON I cannot verify how secure it
can be 



robc

-- 
Robert L. Carbone                   ___                            
                       ___....-----'---`-----....___
                 =========================================
Systems Administrator   ___`---..._______...---'___
Email : robc @
 imsi .
 com  (___)      _|_|_|_      (___)
Phone : (212)339-2742    \\____.-'_.---._`-.____//
                           ~~~~`.__`---'__.'~~~~
                                   `~~~'
                    Investment Management Services Inc.
      That Which Does Not kill you Makes you  hurt that much longer !                
                                                              
                                                          
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.6.2

mQBtAzH0EB0AAAEDAJ9n/Z1pc6huEtmCxn5S9auUm/JY6AqKyvOMesajpgsqa+VW
MVLLTC4EieJf2g5raW3d0GSjm63GNC4PVYbbm4duZfKQfBKPOv9eWuNNxJTYrasp
njcwzkGbedG9AZTO/QAFE7Qdcm9iZXJ0IGNhcmJvbmU8cm9iY0BpbXNpLmNvbT6J
AHUDBRAx9BBBm3nRvQGUzv0BAUqaAv9TAJ5ABDcaL6GHpW+wme1dApkQhE9mNbBU
+Gxe+eulkf/ugFfD1Fdh4+BSM1lk2dDhEc1p8cWTX5WTyzFeJgJo2VJPjsPOG0Zg
1x5v4w7+u5qJeno/8+w2SApTy/ER0sw=
=Zw8h
-----END PGP PUBLIC KEY BLOCK-----








Indexed By Date Previous: Re: Fireballs-Digest V5 #550
From: "william.wells" <william . wells @ damark . com>
Next: Re: DMZ server
From: dharris @ kcp . com (Delmer Harris)
Indexed By Thread Previous: Re: TIMBUKTU
From: Tupshin Harper <tupshin @ tupshin . com>
Next: RE: Dole web site cracked?
From: Alex Filacchione <alexf @ iss . net>

Google
 
Search Internet Search www.greatcircle.com