Skip to content
This repository has been archived by the owner on Jul 13, 2023. It is now read-only.

使用SAMR查询敏感用户 有缺陷 #27

Open
Aixic-Love opened this issue Mar 23, 2020 · 2 comments
Open

使用SAMR查询敏感用户 有缺陷 #27

Aixic-Love opened this issue Mar 23, 2020 · 2 comments

Comments

@Aixic-Love
Copy link

只有初始域管用户被查询的时候ObjectName为objectSid,如果不是即为objectCategory。
导致很难检测出来查询敏感用户。

查询语句 net user "fafa" /domain

如果查询非初始域管用户ObjectType会为SAM_DOMAIN
image

测试环境Server2019

@Qianlitp
Copy link
Owner

你可以简单说一下你的改进办法,提交下PR

@Aixic-Love
Copy link
Author

已经提交了PR

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants