Click here to get back home

Inserting Raw SID Into User Group

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Inserting Raw SID Into User Group Will 02-13-2006
Posted by Will on February 13, 2006, 11:31 pm
Please log in for more thread options
On a computer that was hacked I have a user who created a raw SID in the
Administrator's group that doesn't appear to correspond to any forest on our
network. Before I retire the machine and rebuilt it, I would like to add
the SID in question to a group that is denied access to any resources on the
computer. But I can't add in raw SID's in the User and Computers AD
administration application. Does anyone know how to put a raw SID into a
group? The hacker knew how to do it, apparently. :)

--
Will



Posted by Roger Abell [MVP] on February 14, 2006, 12:37 am
Please log in for more thread options
Note: I have never tried this with a known invalid SID, but I have done
this while the needed trust to verify the SID was inaccessible.

If you script, the normal ways to add a member to a group do accept the
syntax winnt://<sid> instead of the AdsPath for the principal being added.

(so you are about to rebuld the box but first want to deny all access to
that box to the principal the sid represents ??? ok, I believe :-))
--
Roger Abell
Microsoft MVP (Windows Server : Security)

> On a computer that was hacked I have a user who created a raw SID in the
> Administrator's group that doesn't appear to correspond to any forest on
> our
> network. Before I retire the machine and rebuilt it, I would like to
> add
> the SID in question to a group that is denied access to any resources on
> the
> computer. But I can't add in raw SID's in the User and Computers AD
> administration application. Does anyone know how to put a raw SID into a
> group? The hacker knew how to do it, apparently. :)
>
> --
> Will
>
>



Posted by Will on February 14, 2006, 2:30 am
Please log in for more thread options
It's a matter of time. I believe the hacker did his work long ago and
won't be back. The box will be rebuilt when there is time, roughly in two
weeks. In the interim I want to do what I can.

Is there a command line utility that would take the SID as an argument, or
even the winnt://<sid> syntax as input?

--
Will



> Note: I have never tried this with a known invalid SID, but I have done
> this while the needed trust to verify the SID was inaccessible.
>
> If you script, the normal ways to add a member to a group do accept the
> syntax winnt://<sid> instead of the AdsPath for the principal being
added.
>
> (so you are about to rebuld the box but first want to deny all access to
> that box to the principal the sid represents ??? ok, I believe :-))
> --
> Roger Abell
> Microsoft MVP (Windows Server : Security)
>
> > On a computer that was hacked I have a user who created a raw SID in the
> > Administrator's group that doesn't appear to correspond to any forest on
> > our
> > network. Before I retire the machine and rebuilt it, I would like to
> > add
> > the SID in question to a group that is denied access to any resources on
> > the
> > computer. But I can't add in raw SID's in the User and Computers AD
> > administration application. Does anyone know how to put a raw SID into
a
> > group? The hacker knew how to do it, apparently. :)
> >
> > --
> > Will
> >
> >
>
>



Posted by Roger Abell [MVP] on February 14, 2006, 9:58 pm
Please log in for more thread options
Try fileacl although I do not know if it will want to verify the SID
comes from a know account database. Google fileacl

> It's a matter of time. I believe the hacker did his work long ago and
> won't be back. The box will be rebuilt when there is time, roughly in
> two
> weeks. In the interim I want to do what I can.
>
> Is there a command line utility that would take the SID as an argument, or
> even the winnt://<sid> syntax as input?
>
> --
> Will
>
>
>
>> Note: I have never tried this with a known invalid SID, but I have done
>> this while the needed trust to verify the SID was inaccessible.
>>
>> If you script, the normal ways to add a member to a group do accept the
>> syntax winnt://<sid> instead of the AdsPath for the principal being
> added.
>>
>> (so you are about to rebuld the box but first want to deny all access to
>> that box to the principal the sid represents ??? ok, I believe :-))
>> --
>> Roger Abell
>> Microsoft MVP (Windows Server : Security)
>>
>> > On a computer that was hacked I have a user who created a raw SID in
>> > the
>> > Administrator's group that doesn't appear to correspond to any forest
>> > on
>> > our
>> > network. Before I retire the machine and rebuilt it, I would like
>> > to
>> > add
>> > the SID in question to a group that is denied access to any resources
>> > on
>> > the
>> > computer. But I can't add in raw SID's in the User and Computers AD
>> > administration application. Does anyone know how to put a raw SID
>> > into
> a
>> > group? The hacker knew how to do it, apparently. :)
>> >
>> > --
>> > Will
>> >
>> >
>>
>>
>
>



Posted by Jan Hugo Prins on February 17, 2006, 11:33 am
Please log in for more thread options
On Mon, 13 Feb 2006 20:31:03 -0800, Will wrote:

> On a computer that was hacked I have a user who created a raw SID in the
> Administrator's group that doesn't appear to correspond to any forest on
> our network. Before I retire the machine and rebuilt it, I would like
> to add the SID in question to a group that is denied access to any
> resources on the computer. But I can't add in raw SID's in the User and
> Computers AD administration application. Does anyone know how to put a
> raw SID into a group? The hacker knew how to do it, apparently. :)

I think the only reason you see a raw SID is because your system is not
able to find what the name is that belongs to this SID. This SID is
probebly a SID that belongs to the machine or network of the hacker. That
is also the reason that he was able to at is to your ACL, he was able to
resolve it. He did not at a raw SID but he just added his account.

Jan Hugo



Similar ThreadsPosted
Unexpected security restriction for a user in both a user and administrative group. April 24, 2008, 10:05 pm
Restricted User Group November 5, 2005, 3:37 pm
Can't remove user from administrator group November 11, 2005, 2:47 pm
add user to local administrators group May 24, 2006, 4:00 am
?? Can I "clone" a Local User Group ?? January 20, 2008, 11:54 pm
can't login using RDP even in Remote Desktop User group July 6, 2005, 8:54 am
How could I find invisible user in admin group? August 12, 2005, 8:34 am
removing user from domain users group doesn't help June 23, 2006, 4:15 pm
Printer installation & Group Policy / User Rights November 9, 2005, 8:33 am
Code to remove a user group from file or folder ACL March 22, 2006, 1:45 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap