Are there any security risks in two-way trusts?

Hello!
Can anybody enumerate security risks two-way trusts have? Security holes?
I mean two-way trusts between two domains from different forests Windows 2003\2008.
Thank you for any info.

Hi,
There are two potential threats to interforest trust relationships in Windows Server 2003 :
1: Attack on trusting forest by malicious user in a trusted forest :
A malicious user with administrative credentials who is located in a trusted forest could monitor network authentication requests from the trusting forest to obtain the security ID (SID) information of a user who has full access to resources in the trusting
forest, such as a Domain or Enterprise Administrator. SID filtering is set on all trusts by default to help prevent malicious users from succeeding with this form of attack
2: Attack on shared resources in a trusting forest by malicious users in another organization’s forest :
Creating an external or forest trust between two forests essentially provides a pathway for authentications to travel from the trusted forest to the trusting forest. While this action by itself does not necessarily create a threat to either forest, because
it allows all secured communications to occur over the pathway, it creates a larger surface of attack for any malicious user located in a trusted forest. Selective authentication can be set on interforest trusts to help minimize this attack surface area.
For more info , Please refer :
http://technet.microsoft.com/en-us/library/cc755321(v=ws.10).aspx
Though the forest mentioned is on win 2003, this article applies to Win 2008,2008R2 forest environment as well.
Please revert in case of any queries
pankaj(MCT)

Similar Messages

  • Are there any security risks in opening ports for IChat AV?

    Hi all,
    I'm trying to get the network admin on a primarily Windows network to open the ports needed to get iChat AV working, but he is saying it's dangerous to have those ports open, not knowing what kind of effects there would be on a Windows network.
    I am the only Mac user there so as you can see it poses a considerable problem.
    Any help or advice or assurance from network admins to confirm that it is OK to open those ports would be of great help.
    Thanks in advance.
    AW

    Andru08:
    Don't expect your network admin to open any ports. He won't want to put his job on the line for you, nor should you expect him to.
    You MAY be able to route iChatAV over a VPN, although I am still unsuccessful in doing so. I have found that iChatAV works over AIM servers when both source and target are inside the corporate LAN, even though the call registration and setup is initially managed off-net at AOL and Apple (i.e., AOL login and SNATMAP and all that stuff). Theoretically, it would seem like if the outside machine had VPN with the appropriate certificates issued by your network admin (e.g., your home machine if you were wanting to be able to talk work-to-home), the outside machine would act no different than if it was on the corporate LAN.
    In real life, I still haven't gotten my home machine to communicate successfully over VPN to/from work, although I can ftp, afp, telnet, vnc, ssh, imap, smtp, etc., with no problem whatsoever over VPN. Just can't ichat over VPN. So, like me, you're probably SOL until a future version of iChat solves the VPN issue, if that is ever even explored by Apple.
    In the interim, you may just have to have your work go with yahoo messenger or msn messenger on PCs to AV conference to remote offices -- we use something like that at my work for AV conferencing and it traverses VPN just fine to/from our remote offices -- from user desktop/laptop to user desktop/laptop -- just don't know exactly which package we use or how to set it up on Wintel boxes, though, ...coz' I'm a Mac guy. I suppose I could find out for you, though, if you were interested in a Windoze solution...
    If any readers out there have actually gotten iChatAV to work over a VPN, boy, do I (and probably Andru08, too) want to talk to you!

  • I have an imac G5 with a power PC chip running os 10.5.8.  and using safari 5.0.6. are there any security threats i should be aware of?          s there a

    are there any security concerns using my PPC imac g5 running OS 10.5.8 and using Safari 5.0.6?

    You could use a browser that does not use Flash or Java, as a safety measure when visiting sites; the Safari browser has no support or recent updates. TenFourFox v 24 is fairly good, and uses later Mozilla code, is compatible with powerPC computer limitations. SeaMonkeyPPC has a similar code, but acts a little different; and there still is iCab, a good browser that will run free, but asks you get a $20. license.
    The Safari browser can be used to set a different browser up as system default, so it won't launch and open attachments or web pages; it has a setting in its preferences where you choose another browser as default. As I have four or five browsers and one dedicated to gmail (launched as signed-in, through notifier) that is how I've used the default, otherwise mine are all in the Dock.
    There is no new upgrade for Adobe Flash plugin player, etc; but the one in their site for vintage is still available at getflash player at Adobe. Most prompts online are to get you something else, even adware loads up from some not-so-clever efforts to get people to install junk. So go to the source. Someone wrote a patch that is supposed to allow a later version of Flash player to work in older 10.5.8 PPC Mac, but I have not tried it.
    The thread of security is mostly based on the user and their caution to avoid odd free software and also avoid some sites that try to get people to load cleanmymac or genieo, or other adware malware voluntarily. Those are troublesome and hard to remove, and can waste processor cycles, slow the computer & mess it up. Mostly from a browser the adware issues arise. For those you see The Safe Mac and read up on the adware removal guide, among others linked on the page: http://www.thesafemac.com/arg/
    So anyway, there is really nothing new on the face of it for obsolete OS X systems users.
    Good luck & happy computing!

  • HT1222 Are there any security updates for the Mac OS 10.4.11?

    Are there any security updates for my G4 PowerPC OS 10.4.11?

    No. Tiger is an obsolete and unsupported OS at this point. If there were any updates you would find them using Software Update.

  • Are there any security issues with Quicktime player on macbook

    Are there any security issues with Quick Time Player on macbook pro? 2010 model running Yosemite recently upgraded. Thanks!

    No.

  • Are there any differences between these two kinds of constructor

    one pass x a value in a method;
    another not;
    are there any differences when using them?
    ===========
    class ConstructorA
         int x=1,z;
         public ConstructorA(int a){
              z=a;          
    class ConstructorB
         int x,z;
         public ConstructorA(int a){
              x=1;
              z=a;          
    }

    Well the problems would arrive when you add other constructors:
    - if the default value for x is really 1, whatever the way the object is initialized, then it's better to declare it in x's declaration. Otherwise if someone adds to this class a constructor that forgets to set x=1, x's value will remain 0 and bugs may occur.
    - if the default value for x depends on the way it is initialized, then on the contrary it's better to initialize it explicitly in the constructors, and not in x's declaration so as not to have several constructors with inconsistent code.

  • Are there any issues when installing two video cards in the same pc?

    Hello
    I am using Premiere CS5 with a quadro 4000 card. I have two Eizo's monitors attached to the quadro 4000 via the display port. Everything is working fine. I need to connect a plasma screen to my pc (3 monitors total) for viewing red files. I could use the red rocket to export video to the plasma screen but it would be nice if I didn't have to install another driver other than the quadro 4000 nvideo driver. My question is, will having 2 video cards installed in my pc cause any problems? If it will, I will have to use the red rocket for the third monitor. Thanks
    Bill Martz

    Only three obvious drawbacks, provided you have a free PCI-1 16x slot available;
    1. You may need a much more powerful PSU.
    2. You need to improve your cooling significantly.
    3. You need to buy an extra card.

  • HT5639 Are there inherent security risks for installing windows operating systems on a mac?

    Just wondering if I use "bootcamp" and install Windows operating system and find out one of the main reasons I switched to a Mac is because of security issues. I also need to know if I can operate the Mac version of "Microsoft Office" without installing the Windows Operating System.
    Thanks tech savvy people!
    -Navigate100

    Windows concerns are in Windows, OS X in OS X. They do not co-exist because only one system is operational at a time.
    Office 2011 is the OS X version of the suite. Look for it here.

  • Are there any difference between iPhone 4S and iPhone 5? What are they?

    What I already know is that iPhone 5 has a larger screen and is slimmer, but are there any difference between the two.  I have iPhone 4S now, should I buy iPhone 5?

    There are a number of major differences between iPhone 4S and iPhone 5, the major one being the processor speed.  iPhone 5 has a much faster processor – two times faster than the processor in iPhone 4S.  This difference is only significant if you use your phone to play high graphics games that require a lot of processing power.  This processing speed also makes the applications load and run faster – iPhone 5 even boots in a shorter time than iPhone 4S.  You can use iPhone 4S comfortably now but when games and graphic apps designed for iPhone 5 are released, you may be forced to upgrade your phone to run the smoothly.

  • Are there any good tool for checking security risks, Code review, memory leakages for SharePoint projects?

    Are there any good tool for checking security risks, Code review, memory leakages for SharePoint projects?
    I found one such tool "Fortify" in the below link. Are there any such kind of tools available which supports SharePoint?
    Reference: http://www.securityresearch.at/en/development/fortify/
    Amalaraja Fernando,
    SharePoint Architect
    Please Mark As Answer if my post solves your problem or Vote As Helpful if a post has been helpful for you. This post is provided "AS IS" with no warrenties and confers no rights.

    Hi Amalaraja Fernando,
    I'm not sure that there is one more tool that combines all these features. But you may take a look at these solutions:
    SharePoint diagnostic manager
    SharePoint enterprise manager
    What is SPCop SharePoint Code Analysis?
    Dmitry
    Lightning Tools Check
    out our SharePoint tools and web parts |
    Lightning Tools Blog | Мой Блог

  • Are there any ways to increase security in ODI

    Hi,
    Are there any other ways to increase security in ODI. I have heard about External password storage, External authentication and SSO from over here: http://docs.oracle.com/cd/E17904_01/integrate.1111/e12643/whatsnew.htm#CHDEAIAB
    apart from these are there any methods?

    I do not fully understand the meaning of "Top" in the phrase "Top In App Purchase". In Settings there is an option to invoke restrictions. One restriction option is to prohibit In-App Purchases.

  • Since I have the newest version of itunes, I can't back up like normally. The only way is to considilate files and then put them on an external drive which I don't have. Are there any other options? If I can't back up to a disc like I used to, can I inste

    Since I have the newest version of itunes, I can't back up like normally. The only way is to considilate files and then put them on an external drive which I don't have. Are there any other options? If I can't back up to a disc like I used to, can I instead just keep everything on my ipod and then if I have to get a new computer or something just download all my songs from the ipod to my new computer's itunes? Will that work? Will I still be able to keep all my songs that way?

    I'm going to assume the consolidating files does not work due to hard drive space limitations.
    Since you're moving to Windows 7, have you tried using the Windows files and settings transfer utility?  That will move everything for you to the same location on the new computer, it also allows some control over what actually gets moved.
    Alternatively, if you know the location of all of the media, it can be manually moved by copying it from the old computer to the new computer in the same location.
    Also, using the Apple article on moving the library, take a slight twist on what it says.  Move the iTunes library to the external drive, update the settings in iTunes to reflect the library being on the external drive, then consolodate it.
    The options are endless for moving the library... it simply takes a little effort to make it happen and possibly a twist on existing "standard" methods depending on your unique situation.

  • Are there any ways to get sequence number other than getting it for each re

    are there any ways to get sequence number other than getting it for each record

    CACHE is the number of values Oracle stores in memory. So the first call to NEXTVAL Oracle grabs x numbers; subsequent calls to NEXTVAL are served from memory until they're all gone and them another bunch is grabbed. The attached sql*plus output demonstrates this behaviour.
    Note that normally unused numbers in the cache are returned to the data dictionary but in exceptional circumstances (DB crash) they may be lost.
    Cheers, APC
    SQL> create sequence seq cache 3
      2  /
    Sequence created.
    SQL> select last_number from user_sequences
      2  where sequence_name = 'SEQ'
      3  /
    LAST_NUMBER
              1
    SQL> select seq.nextval from dual
      2  /
       NEXTVAL
             1
    SQL> select last_number from user_sequences
      2  where sequence_name = 'SEQ'
      3  /
    LAST_NUMBER
              4
    SQL> select seq.nextval from dual
      2  /
       NEXTVAL
             2
    SQL> select last_number from user_sequences
      2  where sequence_name = 'SEQ'
      3  /
    LAST_NUMBER
              4
    SQL> select seq.nextval from dual
      2  /
       NEXTVAL
             3
    SQL> select last_number from user_sequences
      2  where sequence_name = 'SEQ'
      3  /
    LAST_NUMBER
              4
    SQL> select seq.nextval from dual
      2  /
       NEXTVAL
             4
    SQL> select last_number from user_sequences
      2  where sequence_name = 'SEQ'
      3  /
    LAST_NUMBER
              7
    SQL>

  • Safari was very slow in opening up Google sites.  I found a discussion thread that suggested changing the "Configure IPv6" setting to "Off" in the System Preferences, Network, Advanced, TCP/IP section.  That seems to work well.  Are there any risks?

    Safari was very slow in opening up Google sites.  I found a discussion thread that suggested changing the "Configure IPv6" setting to "Off" in the System Preferences, Network, Advanced, TCP/IP section.  That seems to work well.  Are there any risks to leaving the Configure IPv6 setting to Off?

    Nope. You can always reverse that if you choose.

  • Are there any risks to use native sql in ABAP to access external DB

    here is a requirement to use native sql in abap program to access external DB to load some data into sap. Are there any risks and effects which SAP not recommend ?
    Can anybody show some official document to me because I want to know some risks and dangerous to report to my manager..thanks very much.

    hi Anversha s 
    thank you for your reply
    I means what's the risk when to use native sql to access external DB..
    can you show me some examples about open sql which is used to access external DB...
    Now I am investigating the technique about the connection
    between SAP (by abap program) and external DB...the supporter suggestion is to use native sql to access external DBs.but my manager is afraid of the risks when to use native sql,So I have to report the effective document (example: SAP official document) to explain  to my manager.
    thanks very much

Maybe you are looking for

  • Sale Order Status Change after delivery of materials from projects

    have ETO sccenario which consists of all modules such as SD,PS.PP etc. Materials will be procured from external vendors & manufactured inhouse through project systems. After delivery of materials from project systems, billing & invoicing will be done

  • Saved own colors in swatch palette in start up page

    How can I save my favorite (most used) colors in my swatch palette and use them over and over again? (Means I want to see them at every start up. In earlier versions I could find the "start up page", where I could save them, where it is in CS3?) Than

  • Passing dynamic selection parameters for fagll03 transaction

    hi experts, im trying to call  a transaction ( fagll03) in my report with the input parameters via selection screen (using SUBMIT ) , but iwant to pass the profit center  values to the transaction fagll03 , but the profit center is in dynamic selecti

  • How to merge 2 cts(change request/transport request) into one?

    Hi all, I have created a transport request and my collegue created one and i need to merge his cts of his into mine so that everything falls under one CTS. Thanks Pooja

  • CS4: Font not missing, but glyph doesn't show

    I have a Word 2003 document that I am trying to import as a test file. It has 2 sets of symbols: greater than or equal to and less than or equal to, one set in Times New Roman and the other in Symbol (PostScript). I have InDesign CS2 and CS4 on my co