<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: AD Account Bulk-Unlock, or: Active Directory Denial of Service Attacks</title>
	<atom:link href="http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/</link>
	<description>TechScrawl is a technology blog focusing on a wide variety of technology related areas including enterprise IT, information security, penetration testing, networking, virtualization, and Windows &#38; Linux administration.</description>
	<lastBuildDate>Wed, 03 Mar 2010 23:32:25 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Faiz</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-330</link>
		<dc:creator>Faiz</dc:creator>
		<pubDate>Wed, 03 Mar 2010 23:32:25 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-330</guid>
		<description>define &quot;permissions to unlock&quot;? because using the LockOutStatus tool or active directory, we are able to unlock those accounts which are still locked, even though reported by the scripted to have been unlocked.</description>
		<content:encoded><![CDATA[<p>define &#8220;permissions to unlock&#8221;? because using the LockOutStatus tool or active directory, we are able to unlock those accounts which are still locked, even though reported by the scripted to have been unlocked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clay</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-328</link>
		<dc:creator>Clay</dc:creator>
		<pubDate>Wed, 03 Mar 2010 17:35:22 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-328</guid>
		<description>Are you using an account with permissions to unlock? There is no error checking in the unlock portion of the script, so for example if you run the script with an account that does not have the unlock account permissions, it will report the accounts as unlocked, even when they aren&#039;t.</description>
		<content:encoded><![CDATA[<p>Are you using an account with permissions to unlock? There is no error checking in the unlock portion of the script, so for example if you run the script with an account that does not have the unlock account permissions, it will report the accounts as unlocked, even when they aren&#8217;t.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Faiz</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-327</link>
		<dc:creator>Faiz</dc:creator>
		<pubDate>Wed, 03 Mar 2010 04:39:32 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-327</guid>
		<description>i ran the script, but double checking the same accounts that was reported to be unlocked, using the LockOutStatus tool, it still shows the same account as locked. any ideas what&#039;s going on?</description>
		<content:encoded><![CDATA[<p>i ran the script, but double checking the same accounts that was reported to be unlocked, using the LockOutStatus tool, it still shows the same account as locked. any ideas what&#8217;s going on?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matthew</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-324</link>
		<dc:creator>Matthew</dc:creator>
		<pubDate>Tue, 16 Feb 2010 14:28:00 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-324</guid>
		<description>@Ben/Clay:

The script currently only scans the domain of the account that runs it.  

If you want to run this script against any other domain than the account you&#039;re using to run it, it will require modification.</description>
		<content:encoded><![CDATA[<p>@Ben/Clay:</p>
<p>The script currently only scans the domain of the account that runs it.  </p>
<p>If you want to run this script against any other domain than the account you&#8217;re using to run it, it will require modification.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clay</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-322</link>
		<dc:creator>Clay</dc:creator>
		<pubDate>Thu, 11 Feb 2010 20:54:09 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-322</guid>
		<description>No, it does not need to be run from a DC, and no, it needs no modification.</description>
		<content:encoded><![CDATA[<p>No, it does not need to be run from a DC, and no, it needs no modification.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ben</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-318</link>
		<dc:creator>Ben</dc:creator>
		<pubDate>Tue, 09 Feb 2010 11:54:39 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-318</guid>
		<description>Hi all,

Just a few questions i need answering:

Does this script need to be run from the DC?

Does the script need altering? eg. domain name needs entering.

Thanks

Ben</description>
		<content:encoded><![CDATA[<p>Hi all,</p>
<p>Just a few questions i need answering:</p>
<p>Does this script need to be run from the DC?</p>
<p>Does the script need altering? eg. domain name needs entering.</p>
<p>Thanks</p>
<p>Ben</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Burton Haynes</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-311</link>
		<dc:creator>Burton Haynes</dc:creator>
		<pubDate>Wed, 20 Jan 2010 05:57:33 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-311</guid>
		<description>Hell yeah, this post is really what I am looking for. I am really lucky today. Thank you admin!</description>
		<content:encoded><![CDATA[<p>Hell yeah, this post is really what I am looking for. I am really lucky today. Thank you admin!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lucky worlock</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-309</link>
		<dc:creator>lucky worlock</dc:creator>
		<pubDate>Mon, 11 Jan 2010 05:58:17 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-309</guid>
		<description>Thank you very much... it save me a lot..</description>
		<content:encoded><![CDATA[<p>Thank you very much&#8230; it save me a lot..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mlundy</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-307</link>
		<dc:creator>mlundy</dc:creator>
		<pubDate>Fri, 08 Jan 2010 00:09:53 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-307</guid>
		<description>Is this script run on the DC/</description>
		<content:encoded><![CDATA[<p>Is this script run on the DC/</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Awais</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-285</link>
		<dc:creator>Awais</dc:creator>
		<pubDate>Mon, 23 Nov 2009 19:47:08 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-285</guid>
		<description>I have found the argument, below is how i restrict/filter the search.

ActFilter = &quot;(&amp;(&amp;(ObjectCategory=person)(ObjectClass=user) (UserPrincipalName=MyAccounts*)))&quot;

Thanks
AAA</description>
		<content:encoded><![CDATA[<p>I have found the argument, below is how i restrict/filter the search.</p>
<p>ActFilter = &#8220;(&amp;(&amp;(ObjectCategory=person)(ObjectClass=user) (UserPrincipalName=MyAccounts*)))&#8221;</p>
<p>Thanks<br />
AAA</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Awais</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-284</link>
		<dc:creator>Awais</dc:creator>
		<pubDate>Mon, 23 Nov 2009 16:32:17 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-284</guid>
		<description>Hey,
1st Thanks for th post and the script.
Problem,
when i ran this script it started unlocking all/every account it finds, That is something That I did not want to do.
I want to Only Unlock accounts first that gets locked in today and most important thing about those is I want to only Unlock specific account For Example
UNLOCK ALL Accounts WHERE Account_Name LIKE &#039;DELL%&#039;
Mean unlock all account where account name starts with &#039;DELL&#039;

I&#039;ll greatly appreciate any help on this.

Thanks.</description>
		<content:encoded><![CDATA[<p>Hey,<br />
1st Thanks for th post and the script.<br />
Problem,<br />
when i ran this script it started unlocking all/every account it finds, That is something That I did not want to do.<br />
I want to Only Unlock accounts first that gets locked in today and most important thing about those is I want to only Unlock specific account For Example<br />
UNLOCK ALL Accounts WHERE Account_Name LIKE &#8216;DELL%&#8217;<br />
Mean unlock all account where account name starts with &#8216;DELL&#8217;</p>
<p>I&#8217;ll greatly appreciate any help on this.</p>
<p>Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mike</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-280</link>
		<dc:creator>mike</dc:creator>
		<pubDate>Tue, 03 Nov 2009 17:02:03 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-280</guid>
		<description>Just had to say thanks on this. Blew up my certs on my domain controllers and locked out everyone (21,000 accounts).  fixed the cert and a frantically googled a way to mass unlock accounts. I was in the clear in 5 minutes. IOU one big beer.</description>
		<content:encoded><![CDATA[<p>Just had to say thanks on this. Blew up my certs on my domain controllers and locked out everyone (21,000 accounts).  fixed the cert and a frantically googled a way to mass unlock accounts. I was in the clear in 5 minutes. IOU one big beer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Clay</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-268</link>
		<dc:creator>Clay</dc:creator>
		<pubDate>Fri, 11 Sep 2009 12:55:57 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-268</guid>
		<description>Hi Joseph. This solution is still possible because the builtin Active Directory administrator account can never really be locked out. As long as you know the password, it is possible to log on to a domain controller with that account. This is one good reason to not disable that account, although renaming it and securing it with a strong password are a good idea. Hope that helps.</description>
		<content:encoded><![CDATA[<p>Hi Joseph. This solution is still possible because the builtin Active Directory administrator account can never really be locked out. As long as you know the password, it is possible to log on to a domain controller with that account. This is one good reason to not disable that account, although renaming it and securing it with a strong password are a good idea. Hope that helps.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joseph</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-267</link>
		<dc:creator>Joseph</dc:creator>
		<pubDate>Fri, 11 Sep 2009 01:42:39 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-267</guid>
		<description>Is this solution possible if I am log-in using the guest account? because our active directory administrator account was also locked.</description>
		<content:encoded><![CDATA[<p>Is this solution possible if I am log-in using the guest account? because our active directory administrator account was also locked.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gavin Hamill</title>
		<link>http://blog.techscrawl.com/2008/09/16/ad-account-bulk-unlock-or-active-directory-denial-of-service-attacks/#comment-264</link>
		<dc:creator>Gavin Hamill</dc:creator>
		<pubDate>Sat, 29 Aug 2009 13:54:40 +0000</pubDate>
		<guid isPermaLink="false">http://clayshek.wordpress.com/?p=175#comment-264</guid>
		<description>This issue has thankfully now been traced to a remote machine with a virus on a bridged VPN. 

I did try Lockoutstatus.exe yesterday as part of the troubleshooting but found that it misreported thus adding confusion. We have 3 DCs, of which two were marked &#039;Unlock (Auto Unlock)&#039; despite the fact that the account in question was definitely locked. 

My stumbing was in the Windows security log - I was looking for one of the columns to show the locked username.  My bad - in the end all I had to do was look in a couple of the &#039;Failed Audit&#039; entries and I was presented with the most-recently locked username along with the IP of the workstation.  I then firewalled it from everything but the DHCP server (fortunately DHCP is not run by the DCs!) so it would stick on the same IP.

I&#039;m looking forward to slinging all hell at the sysadmins of that remote site on Monday since their incompetence damaged my Friday night. :)</description>
		<content:encoded><![CDATA[<p>This issue has thankfully now been traced to a remote machine with a virus on a bridged VPN. </p>
<p>I did try Lockoutstatus.exe yesterday as part of the troubleshooting but found that it misreported thus adding confusion. We have 3 DCs, of which two were marked &#8216;Unlock (Auto Unlock)&#8217; despite the fact that the account in question was definitely locked. </p>
<p>My stumbing was in the Windows security log &#8211; I was looking for one of the columns to show the locked username.  My bad &#8211; in the end all I had to do was look in a couple of the &#8216;Failed Audit&#8217; entries and I was presented with the most-recently locked username along with the IP of the workstation.  I then firewalled it from everything but the DHCP server (fortunately DHCP is not run by the DCs!) so it would stick on the same IP.</p>
<p>I&#8217;m looking forward to slinging all hell at the sysadmins of that remote site on Monday since their incompetence damaged my Friday night. :)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
