OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Laura A. Robinson (larobins_at_bellatlantic.net)
Date: Fri Jan 24 2003 - 01:59:16 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    LDIFDE or CSVDE, although they just do text dumps of the configuration and
    accounts and won't maintain SIDs. You could use ADMT v2 to migrate from the
    infected domain into a clean domain, and it does migrate passwords.

    Laura

    > -----Original Message-----
    > From: Dan Uscatu [mailto:duscatulunatech.ro]
    > Sent: Thursday, January 23, 2003 3:17 AM
    > To: focus-mssecurityfocus.com
    > Subject: w2k server compromised
    >
    >
    > hey all
    >
    > i just found one of the w2k servers to be infected and acting
    > very strangely. unfortunately it is a domain controller and
    > it has all the users/computers lists.
    >
    > how can i export these before reinstall in order to keep the
    > exact same configuration (everything except passwords of
    > course) ? i suppose this could be usefull to be done on a
    > regular basis too...
    >
    > TIA
    >
    >