Computer Genius siezes control of San Francisco

N&P: Discuss governments, nations, politics and recent related news here.

Moderators: Alyrium Denryle, Edi, K. A. Pital

User avatar
Spyder
Sith Marauder
Posts: 4465
Joined: 2002-09-03 03:23am
Location: Wellington, New Zealand
Contact:

Post by Spyder »

Resinence wrote:
Spyder wrote: Is that just a danger while the domain admin is using the system or can they do something along the lines of exploiting the local profile?
Let's say your a local admin, and you want to be a domain admin;

Start digging through the system, chuck a bunch of registry autostart entries to start a small program or script that once executed will create a new user account with xx username and yy password, with full domain access. Since you are only a local admin, you can't create a domain admin account, obviously. But now that the system has been messed with all you have to do is wait for Mr. Admin to log onto that machine, script/prog autostarts... with his permissions. BAM! Account.
Ah, should have thought of that. *hugs runas*
:D
Post Reply