Re: Local Administrators

bo.berlas_at_gsa.gov
Date: 12/30/03

  • Next message: Yvan Boily: "RE: compromised network"
    To: John.VanMeter@ost.dot.gov
    Date: Tue, 30 Dec 2003 13:09:59 -0500
    
    

    Open a null session to the box and use dumpsec to determine group members:

    1) @command prompt: net use \\ipaddress\ipc$ "" /user:""
    2) You can download dumpsec - http://www.somarsoft.com/

    Bo Berlas, CISSP
    Program Expert, IT Security Division
    O: 202.501.2450 M: 202.236.6304 F: 202.219.4257
    bo.berlas@gsa.gov
    http://www.gsa.gov

    DH/DSS Fingerprint
    7758 EE4B C14E 59F9 5B44 1A71 1A81 7420 9DAE 53D4

                                                                                                                           
                                                                                                                           
                        "Van Meter, John" To: security-basics@securityfocus.com
                        <John.VanMeter@os cc: (bcc: Bo Berlas/IAS/CO/GSA/GOV)
                        t.dot.gov> Subject: Local Administrators
                                                                                                                           
                        12/30/2003 05:46
                        AM
                                                                                                                           
                                                                                                                           

    Is there an easy way to find out what users are in the local admin group?
    The workstations are Win2k Pro SP4, I was thinking about using adduser from
    the resource kit, but it takes several lines of code to do it that way.

    Thank You
    John van Meter

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Yvan Boily: "RE: compromised network"