I got a website where all users are stored in an AD.
The users can change their password through the website.
But everytime a user changes it's password a folder in "x:\Documents and Settings" with the AD-username on the webserver is created!
Like this:
C:\Documents and Settings\Administrator
C:\Documents and Settings\All Users
C:\Documents and Settings\Default User
C:\Documents and Settings\Donald43 (a user in the AD that have set his pass through the web)
C:\Documents and Settings\Fredric2 (another user)
C:\Documents and Settings\Garfield62 (and so on..)
C:\Documents and Settings\Harry23
C:\Documents and Settings\Lokko23
etc etc
I got over 2600 of these folders now! :) (130 000 files, and 117 000 sub-folders 1.75GB!!!)
This started happening after a an upgrade of the web. But no changes had been made to the "set password"-code. And the AD itself has not been touched.
(Users that does not change their password does not have a folder.)
I dont know where to look.
All ideas would be appreciated.
None
0 Points
1 Post
Huge security blunder? Bit of a fun too.. :)
Aug 13, 2006 06:19 AM|ted1001|LINK
Hey!
I got a website where all users are stored in an AD.
The users can change their password through the website.
But everytime a user changes it's password a folder in "x:\Documents and Settings" with the AD-username on the webserver is created!
Like this:
C:\Documents and Settings\Administrator
C:\Documents and Settings\All Users
C:\Documents and Settings\Default User
C:\Documents and Settings\Donald43 (a user in the AD that have set his pass through the web)
C:\Documents and Settings\Fredric2 (another user)
C:\Documents and Settings\Garfield62 (and so on..)
C:\Documents and Settings\Harry23
C:\Documents and Settings\Lokko23
etc etc
I got over 2600 of these folders now! :)
(130 000 files, and 117 000 sub-folders 1.75GB!!!)
This started happening after a an upgrade of the web. But no changes had been made to the "set password"-code. And the AD itself has not been touched.
(Users that does not change their password does not have a folder.)
I dont know where to look.
All ideas would be appreciated.
Webserver: Windows 2003 Server
AD: Windows 2000