Full Disclosure mailing list archives
RE: Full-Disclosure Digest, Vol 19, Issue 9
From: "Tyler, Grayling" <ggtyler () foodlion com>
Date: Fri, 8 Sep 2006 07:33:15 -0400
The short answer is, no it does not get updated. In-fact, up until windows 2003 it was only updated on the domain controller which serviced the authentication request and even on 2003 it doesn't replicate quickly enough to allow you to query just one DC to obtain an definitive answer without checking and comparing the values listed on the other DC in the domain Message: 8 Date: Thu, 7 Sep 2006 19:16:05 -0700 From: <deji () akomolafe com> Subject: RE: [Full-disclosure] Active Directory accounts To: <full-disclosure () lists grok org uk> Message-ID: <D0F4A609-60A7-49C9-B137-BFFA2A55F02E@mimectl> Content-Type: text/plain; charset="iso-8859-1" I'm sorry for the people who let you "pull off" data from their AD. If you don't know how or when lastlogon is touched, you have no business doing what you are doing. Deji ________________________________ From: Steven Rakick Sent: Thu 9/7/2006 1:36 PM To: full-disclosure () lists grok org uk Subject: [Full-disclosure] Active Directory accounts Hello, I have a question regarding some data I pulled off a customers AD. We recently ran AD scan to identify several user accoutn violation types using AD Inspector (www.obtuse.net/software/adinspector). Basically the search contained filters for users who dont have password expirations enabled and also users who havent logged in in the last 90 days (stale accounts). Anyways, the results were quite suprising and I'd like to validate them. My question is this. Is the lastLogon AD account property updated any time a user authenticates to AD regardless of the service? Like, if I login to a 3rd party application which uses LDAP integration with AD for authentication, will that update the users lastLogon property in AD? __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ ************************************************************************** This electronic message may contain confidential or privileged information and is intended for the individual or entity named above. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited. If you have received this electronic transmission in error, please notify the sender immediately by using the e-mail address or by telephone (704-633-8250). ************************************************************************** _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- RE: Full-Disclosure Digest, Vol 19, Issue 9 Tyler, Grayling (Sep 08)