OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Local Admins

From: simonis (simonismyself.com)
Date: Fri Sep 05 2003 - 14:36:46 CDT


CHM Security wrote:
>
> Is there an easy way to scan 2K/XP machines to determine who is a member of
> the administrator groups? We are having a lot of problems with our IT
> personnel adding local users as admins on their boxes which is causing us
> lots of problems. We just found one user who was hitting cancel everytime
> the SUS would send updates to her machine because it wasn't convenient. We
> have over 1000 machines in our domain and I really don't want to try and run
> this manually, especially when there is a chance some tech might come behind
> and start adding them back.
>

Theres a tool called locals, I think from the resource kit, that will
remotely list members of specified groups. Writing a cmd or perl
script to automate discovery would be easy enough.

---------------------------------------------------------------------------
KaVaDo provides the first and only integrated Web application scanner and
firewall security suite that prevent Web applications attacks, the most
common form of online exploitation. Download a FREE whitepaper on Security Policy Automation for Web Applications.
http://www.securityfocus.com/sponsor/KaVaDo_focus-ms_030818
---------------------------------------------------------------------------