[Full-Disclosure] W2k users, local admin rights and GPOs

Sergey V. Gordeychik gordey at infosec.ru
Wed Oct 29 14:48:01 GMT 2003


So, I got an idea.
Everybody, who can drop pings, or SMB commutations, from his local
machine to DC can prevent GPO updates!
User can use IPSec policy (sic!) to do it :-)
So, Laura right :-)
And I'm wrong :-(




Full-Disclosure is hosted and sponsored by Secunia.