Administration in Security Perspective Homepage
Forum Home Forum Home > Information Security > VAPT
  New Posts New Posts RSS Feed: Active Directory Vulnerability Assessment
  FAQ FAQ  Forum Search   Register Register  Login Login


This message is in display since you have logged in as Guest! You need to register yourself to post and reply topics.

Benefits of membership
* Posting and earning Stars
* Copy Right Protection to your articles
* Community peoples

And much more...

Active Directory Vulnerability Assessment

 Post Reply Post Reply
Author
Message
Admin View Drop Down
Forum Administrator
Forum Administrator
Avatar
Root Administrator

Joined: 23 Jun 2009
Location: Qatar
Online Status: Offline
Posts: 714
Post Options Post Options   Quote Admin Quote  Post ReplyReply Direct Link To This Post Topic: Active Directory Vulnerability Assessment
    Posted: 08 Jan 2010 at 5:26am
[Tutorial]
 
I recently conducted an Internal Vulnerability Assessment on various servers using some free and commercial tools. I would like to share some of those tools and also like to listen your recommendations and suggestions too. We shall begin with Active Directory, where all information about the domain, user credentials and network information of an organization are stored in a server. Active Directory server i.e; Domain Controller is a critical server for any organization, where by any chance if poorly configured can lead to misuse of information, leakage of confidential data and so on. So, I would post here the tools that I had used to carryout Vulnerability Assessment on Active Directory and meanwhile, you can also share your tools and suggestions here. Smile


Edited by Admin - 08 Jan 2010 at 5:27am
Back to Top
Admin View Drop Down
Forum Administrator
Forum Administrator
Avatar
Root Administrator

Joined: 23 Jun 2009
Location: Qatar
Online Status: Offline
Posts: 714
Post Options Post Options   Quote Admin Quote  Post ReplyReply Direct Link To This Post Posted: 10 Jan 2010 at 9:26pm
MaxPowerSoft Active Directory Reports

This tool works well in Windows 2008/2003/2000 and NT based Active Directory Servers. It's a commercial tool but the trial period is enough to do your auditing stuff on Active Directory. Below are some of auditing data that I usually retrieve from DC using this tool
  • Default Domain Policy and Default Domain Controllers Policy
  • Password Last set period of Administrator account
  • Users with allowed Dial-in access
  • Domain computers without service pack
  • Members of Administrator Group, Enterprise Admins Group, Domain Administrators Group
  • List of users with never password option
  • List of users who have never logged in
  • Users with hidden mailboxes
There are also many scripts and free tools available in the market, but this one does the job quiet easier. Just by adding domain and authenticating domain privilege, MaxPowerSoft AD reports would retrieve all required auditing information.


Back to Top
Admin View Drop Down
Forum Administrator
Forum Administrator
Avatar
Root Administrator

Joined: 23 Jun 2009
Location: Qatar
Online Status: Offline
Posts: 714
Post Options Post Options   Quote Admin Quote  Post ReplyReply Direct Link To This Post Posted: 10 Jan 2010 at 9:29pm
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down

Bulletin Board Software by Web Wiz Forums® version 9.61
Copyright ©2001-2009 Web Wiz