Re: Inserting Raw SID Into User Group



On Mon, 13 Feb 2006 20:31:03 -0800, Will wrote:

On a computer that was hacked I have a user who created a raw SID in the
Administrator's group that doesn't appear to correspond to any forest on
our network. Before I retire the machine and rebuilt it, I would like
to add the SID in question to a group that is denied access to any
resources on the computer. But I can't add in raw SID's in the User and
Computers AD administration application. Does anyone know how to put a
raw SID into a group? The hacker knew how to do it, apparently. :)

I think the only reason you see a raw SID is because your system is not
able to find what the name is that belongs to this SID. This SID is
probebly a SID that belongs to the machine or network of the hacker. That
is also the reason that he was able to at is to your ACL, he was able to
resolve it. He did not at a raw SID but he just added his account.

Jan Hugo


.



Relevant Pages

  • Re: Inserting Raw SID Into User Group
    ... this while the needed trust to verify the SID was inaccessible. ... Before I retire the machine and rebuilt it, ... the SID in question to a group that is denied access to any resources on ... Does anyone know how to put a raw SID into ...
    (microsoft.public.windows.server.security)
  • Re: Multiple profile migration using ADMT
    ... How To Use Microsoft Visual Basic to Convert a Raw SID into a String SID ... the SID history - voila - the sam names are all matched.... ...
    (microsoft.public.windows.server.migration)
  • Re: Inserting Raw SID Into User Group
    ... Try fileacl although I do not know if it will want to verify the SID ... Google fileacl ... Does anyone know how to put a raw SID ...
    (microsoft.public.windows.server.security)
  • Re: Inserting Raw SID Into User Group
    ... I have never tried this with a known invalid SID, ... this while the needed trust to verify the SID was inaccessible. ... the SID in question to a group that is denied access to any resources on ... Does anyone know how to put a raw SID into a ...
    (microsoft.public.windows.server.security)
  • RE: SIDS show instead of user names
    ... I'd like to make sure the sid can be resolved at the same time you see SID ... As far as the accounts being deleted in AD, ... Go to Capture --> Networks to choose the correct network card by ...
    (microsoft.public.win2000.active_directory)