Full Disclosure mailing list archives
Active Directory accounts
From: Steven Rakick <stevenrakick () yahoo com>
Date: Thu, 7 Sep 2006 13:36:24 -0700 (PDT)
Hello, I have a question regarding some data I pulled off a customers AD. We recently ran AD scan to identify several user accoutn violation types using AD Inspector (www.obtuse.net/software/adinspector). Basically the search contained filters for users who dont have password expirations enabled and also users who havent logged in in the last 90 days (stale accounts). Anyways, the results were quite suprising and I'd like to validate them. My question is this. Is the lastLogon AD account property updated any time a user authenticates to AD regardless of the service? Like, if I login to a 3rd party application which uses LDAP integration with AD for authentication, will that update the users lastLogon property in AD? __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Active Directory accounts Steven Rakick (Sep 07)
- RE: Active Directory accounts deji (Sep 07)
- Re: Active Directory accounts Philosophil (Sep 08)
- Message not available
- Re: Active Directory accounts Philosophil (Sep 08)
- Message not available
- <Possible follow-ups>
- RE: Active Directory accounts Angel Barrio (Sep 08)
- RE: Active Directory accounts Steven Rakick (Sep 08)
- RE: Active Directory accounts Angel Barrio (Sep 08)