OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Reinder Wiersma (reinder.wiersmaCMG.NL)
Date: Wed Feb 07 2001 - 04:25:28 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    Robin,

    De andere mogelijkheid om Admin te worden staat op:
    http://www.atstake.com/research/advisories/2001/index.html#020501-1
    Ik ga dit nog verder uitzoeken.

    Reinder.

    -----Original Message-----
    From: Gary Flynn [mailto:flynngnJMU.EDU]
    Sent: dinsdag 6 februari 2001 18:07
    To: PEN-TESTSECURITYFOCUS.COM
    Subject: Re: [PEN-TEST] Expand right under Win2K

    > We have a win2k where we have access to a cmd.exe with the rights of the
    > web-server and we would like to obtain administrator rights. Also we
    > don't have the rights to read the SAM files.
    > We tried the well-known methdos under win NT 4.0 (like breaknt.exe,
    > read from raw device) in vain.
    > Has anyone any idea what to be next step to administrator rights?

    It looks like a new approach has just been made available....

    http://www.microsoft.com/technet/security/bulletin/MS01-007.asp

    --
    

    Gary Flynn Security Engineer - Technical Services James Madison University

    Please R.U.N.S.A.F.E. http://www.jmu.edu/computing/info-security/engineering/runsafe.shtml