RE: more info on a hopefully unsuccessful compromise

From: David Vincent (david.vincentat_private)
Date: Mon Jul 14 2003 - 13:35:08 PDT

  • Next message: james: "Fw: qmail smtp-auth bug allows open relay"

    moderator oh moderator - please let this one through as it is clearly on
    topic.
    
    
    
    i've been browsing through this thread, and haven't seen anyone mention
    sid2user and user2sid yet.
    
    http://www.chem.msu.su/~rudnyi/NT/
    
    any chance they can help? 
    
    > Administrator is the default name of the account w/ an
    > RID of 500, one then has to ask, did you change the
    > name of the default Administrator account?
    
    would help finding out who is actually holding that RID.
    
    -d
    
    
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Tue Jul 15 2003 - 10:56:33 PDT