In the example scripts I noticed that the maintenance server scripts are located in a hidden share which may be readable to all users. The log and db directories within that share are written to from the login script.

What keeps a user from reading your maintenance scripts and getting the domain admin account you have there?