Win2K3 Priv Escalation

看板Bugtraq作者時間18年前 (2007/11/28 10:20), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/3 (看更多)
Alright, i follow bugtraq rather extensively and really never had much to say, but a friend of mind just contacted me earlier with a problem and i can't really think of a simple solution. Anyway, I'm hoping someone can help. Scenario Companies previous net admin was ticked he was getting laid off and removed all users from the Domain Admin group, and the local account password has been changed to something no one in the company knows. Well, he tried to reset the admin password(local) using chgntpw(i think thats it *nix app) and it complains that flags on the filesystem are invalid and to login to safe mode, reboot, ect. Which he can't do. The question is, is there any simple way to gain administrative privileges(preferably domain admin) on win2K3? I've thought of process injection, possibly a rk, something along those lines, which would either need to be made from scratch or modified to his specific needs. But all that just seems over kill when all he needs to do is add a domain admin acct so he can start being the net admin. Open to suggestions, flaming because i'm retarded and missing it, ect. Thanks
文章代碼(AID): #17JD1u00 (Bugtraq)
文章代碼(AID): #17JD1u00 (Bugtraq)