Solved

Step to find out about server information,

Posted on 2006-06-12
2
200 Views
Last Modified: 2010-05-18
http://www.theiia.org/ITAudit/index.cfm?act=itaudit.archive&fid=5622
"
To make a manual anonymous connection, users need to run the following command from a command prompt:

     Net use \\<server ip address>\ipc$ /u:"" "" 

In this example, the user includes the server's Internet protocol address in the command (e.g., 10.10.10.10). The /u switch denotes the user account that is being employed to authenticate to the server — a null user account in this case or anonymous user connection.

After the anonymous connection is established, the user can access various security configurations on that server. The information that an attacker connecting as the anonymous user gathers is typically used in conjunction with other tools or attack methods. Such information includes:

    * Lists of computer users, including those in the Active Directory.
    * Lists of groups from the computer, including the Active Directory.
    * Security identifiers (SIDs) for user accounts.
    * User accounts for SIDs.
    * List of shared folders.
    * Account policies.
    * NetBIOS name.
    * Domain name with which the computer is associated.
    * List of trusted domains.
"

I do understand you can see all the shared folders after you execute the command above(  Net use \\<server ip address>\ipc$ /u:"" "" ). By going to that computer on you my computer //servername
But I don't understand how you can get the list of computer users using anonymous connection.
Can someone give me a demo?

0
Comment
Question by:kecoak
2 Comments
 
LVL 14

Accepted Solution

by:
canali earned 500 total points
ID: 16892526

Set objDomain = GetObject("WinNT://<server ip address>")
objDomain.Filter = Array("User")

For Each objUser In objDomain
    Wscript.Echo objUser.Name
Next

Gas
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
So you have two Windows Servers and you have a directory/folder/files on one that you'd like to mirror to the other?  You don't really want to deal with DFS or a 3rd party solution like Doubletake. You can use Robocopy from the Windows Server 200…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question