<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:series="http://unfoldingneurons.com/"
		>
<channel>
	<title>Comments on: How to handle the built-in administrator account</title>
	<atom:link href="http://4sysops.com/archives/how-to-handle-the-built-in-administrator-account/feed/" rel="self" type="application/rss+xml" />
	<link>http://4sysops.com/archives/how-to-handle-the-built-in-administrator-account/</link>
	<description>For Windows Administrators</description>
	<lastBuildDate>Sat, 21 Nov 2009 11:14:56 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: David</title>
		<link>http://4sysops.com/archives/how-to-handle-the-built-in-administrator-account/comment-page-1/#comment-128042</link>
		<dc:creator>David</dc:creator>
		<pubDate>Thu, 04 Jun 2009 00:53:50 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/?p=2899#comment-128042</guid>
		<description>&gt;&gt; However, if an attacker manages to enable the admin account (for example, if he has physical access to the machine), he can just set a password which will enable him to manage the machine remotely.

If the attacker has physical access to the machine, it doesn&#039;t matter if the password is blank or not.</description>
		<content:encoded><![CDATA[<p>&gt;&gt; However, if an attacker manages to enable the admin account (for example, if he has physical access to the machine), he can just set a password which will enable him to manage the machine remotely.</p>
<p>If the attacker has physical access to the machine, it doesn&#8217;t matter if the password is blank or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Pietroforte</title>
		<link>http://4sysops.com/archives/how-to-handle-the-built-in-administrator-account/comment-page-1/#comment-128006</link>
		<dc:creator>Michael Pietroforte</dc:creator>
		<pubDate>Tue, 02 Jun 2009 09:26:14 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/?p=2899#comment-128006</guid>
		<description>Mathew, thanks. Auditing  activities related to the administrator account certainly is a good idea. The problem is that there are so many things to audit. Intrusion detection is a difficult business.

Simplify PC Solutions, as far as I know the only noteworthy difference is related to UAC. Since XP has no UAC, the built-in administrator behaves like any other admin account.</description>
		<content:encoded><![CDATA[<p>Mathew, thanks. Auditing  activities related to the administrator account certainly is a good idea. The problem is that there are so many things to audit. Intrusion detection is a difficult business.</p>
<p>Simplify PC Solutions, as far as I know the only noteworthy difference is related to UAC. Since XP has no UAC, the built-in administrator behaves like any other admin account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simplify PC Solutions</title>
		<link>http://4sysops.com/archives/how-to-handle-the-built-in-administrator-account/comment-page-1/#comment-127996</link>
		<dc:creator>Simplify PC Solutions</dc:creator>
		<pubDate>Mon, 01 Jun 2009 22:07:47 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/?p=2899#comment-127996</guid>
		<description>Great stuff! One question: How do Vista/Windows 7&#039;s admin account capabilities compare with XP&#039;s?</description>
		<content:encoded><![CDATA[<p>Great stuff! One question: How do Vista/Windows 7&#8217;s admin account capabilities compare with XP&#8217;s?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mathew Locke</title>
		<link>http://4sysops.com/archives/how-to-handle-the-built-in-administrator-account/comment-page-1/#comment-127994</link>
		<dc:creator>Mathew Locke</dc:creator>
		<pubDate>Mon, 01 Jun 2009 20:52:49 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/?p=2899#comment-127994</guid>
		<description>Very good article. If more admins were to follow this practice, I&#039;d have less work to do on the security side. One thing you might include is to alert or at least audit when someone tries to use the disabled administrator account. Tell tail sign of a bad guy.</description>
		<content:encoded><![CDATA[<p>Very good article. If more admins were to follow this practice, I&#8217;d have less work to do on the security side. One thing you might include is to alert or at least audit when someone tries to use the disabled administrator account. Tell tail sign of a bad guy.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
