userAccountControl设置为8192作为后门

来源推特:https://twitter.com/kaidja/status/1480212323818217479

userAccountControl属性含义

creatorsid可以修改机器的userAccountControl但是不能改为8192

并且修改userAccountControl后primaryGroupId也会随之改变

515 – Domain Computers
516 – Domain Controllers (writable)
521 – Domain Controllers (Read-Only)

即userAccountControl更改之后groupid从515变为516

查看域内域控也会显示

  • Created 2022-10-22 12:13
  • Published 2022-01-12 12:34
  • Updated 2022-10-24 10:04