Professional Documents
Culture Documents
Looking Up A SID of Any Domain Account
Looking Up A SID of Any Domain Account
While learning what SID is, I have written two utilities, user2sid and
sid2user, which are actually command line interfaces to WIN32 functions,
LookupAccountName and LookupAccountSid. So, no hacking, just what is
permitted by MS.
S-1-5-21-201642981-56263093-24269216-513
Now we know all the subauthorities for the current domain. All the
domain account SIDs are different by the last number only (so called RID).
Name is SmallUser
Domain is DomainName
Type of SID is SidTypeUser
3) Now it is possible to look up all the domain accounts from the very
first one (RID = 1000 for the first account, 1001 for the second and so
on, RIDs are never used again for the current installation).
Well, this is not the end of the story. The anonymous logon is also in
the EVERYONE group. This means that actually it is possible to find out
who is a built-in administrator and to see the history of the SAM at any
domain into which you can run the anonymous session. Note that anonymous
sessions are not audited by logon/logoff category.
Non-authoritative answer:
Name: www.xyz.com
Address: 131.107.2.200
S-1-5-21-201642981-56263093-24269216-513
Number of subauthorities is 5
Domain is XYZ_domain
Length of SID in memory is 28 bytes
Type of SID is SidTypeGroup
Name is XYZAdmin
Domain is XYZ_domain
Type of SID is SidTypeUser
Name is
Domain is XYZ_domain
Type of SID is SidTypeDeletedAccount
Name is Simpson
Domain is XYZ_domain
Type of SID is SidTypeUser
SP3 does not prevent this to happen (at least without further manual
editing the registry).
For those who would like to try it, the utilities can be found at my
homepages
http://www.chem.msu.su/~rudnyi/NT/sid.zip
The file is about 50 Kb, the link may be slow though. I give them to
public domain, feel free to publish them from your servers if you want
it to.
Good hunting,
Evgenii Rudnyi
--
Chemistry Department rudnyi@comp.chem.msu.su
Moscow State University http://www.chem.msu.su/~rudnyi/welcome.html
119899 Moscow +7(095)939 5452, fax+7(095)932 8846,+7(095)939 1205
Russia