Forum: SuRun English speaking RSS
Surun account
geoholz #1
Mitglied seit 02/2016 · 1 Beitrag
Gruppenmitgliedschaften: Mitglieder
Profil anzeigen · Link auf diesen Beitrag
Betreff: Surun account
Hello,

Is there a possibility to change the user account used by Surun ?

I want to use a domain account instead of local administrator account

Thanks
Kay (Administrator) #2
Benutzertitel: Weltverbesserer
Mitglied seit 11/2007 · 1469 Beiträge · Wohnort: Magdeburg
Gruppenmitgliedschaften: Administratoren, Mitglieder
Profil anzeigen · Link auf diesen Beitrag
Hello geoholz,

using a domain admin account is not possible without modifying SuRun.

The SuRun service runs with "local system" credentials. Usually domain controllers don't trust local systems and deny adding domain users to the domain admins group.

When creating SuRun I thought that there's to much attack surface to safely use a domain admin account.

To use a domain admin account SuRun would have to:
-locally store domain admin credentials (insecure)
-logon the domain admin to get a token from the domain controller (the token could be sniffed)
-impersonate as the domain admin
-put the domain user into the domain admins group
-logon the user as domain admin to get another admin token (that could be sniffed)
-remove the user from the domain admin group (in the time, the last three steps would take, the user could logon as domain admin; also if one would cut the server connection, the user would become domain admin forever)

Cheers,

Kay
Schließen Kleiner – Größer + Auf diesen Beitrag antworten:
Prüfcode: VeriCode Gib bitte das Wort aus dem Bild ins folgende Textfeld ein. (Nur die Buchstaben eingeben, Kleinschreibung ist in Ordnung.)
Smileys: :-) ;-) :-D :-p :blush: :cool: :rolleyes: :huh: :-/ <_< :-( :'( :#: :scared: 8-( :nuts: :-O
Weitere Zeichen:
Gehe zu Forum
Nicht angemeldet. · Kennwort vergessen · Registrieren
This board is powered by the Unclassified NewsBoard software, 20150713-dev, © 2003-2015 by Yves Goergen
Seite erstellt in 69,1 ms (19,1 ms) · 44 Datenbankabfragen in 16,5 ms
Aktuelle Zeit: 18.10.2017, 20:30:36 (UTC +02:00)