帐号解剖安全帐号管理器(sam)结构(Anatomical safety Account Manager (SAM) structure)

帐号安全  时间:2021-03-14  阅读:()

解剖安全帐号管理器(sam)结构Anatomical safety Account

Manager (SAM) structure

Article source: www.opengram.com

Article submission: refdom

HomePage: www.opengram.com

I, abstract

I I, about SAM

III, the SAM database structure in the registry

The structure and main content of IV and SAM databaseV, conclusions about SAM database analysis

I. s umm ary

The analysis of the security account manager structure was donemore than a month ago and only fragmentary records were notposted. The main issue is not released

The reason is that the security account manager (SAM) is thecore of WIN system account management, and it' s very systematic,and I also have a lot of room for just pushing

Break and guess, while SAM hack may cause the lsass.exe to loadaccount manager error when started, even security mode can not

be repaired (start up)

It must load SAM) to cause the whole system to start crashing(I usually need to rely on the second system to delete the SAMfile to start it) . As for now released

That is mainly because the Adam and the "Administrator" Dingclone described rootkit way of concealment and harmfulness, thestructure of SAM

Familiarity can help security personnel to do security testing(and, of course, to make use of undesirable candidates) .The contents of SAM are only introduced here, and the Securityrelated ones are not public for the time being.

Two, about SAM

Don' t get it wrong, SAM, it' s not a file, Sam is so simple. SAM(Security Accounts Manager security account manager) isresponsible for

Control and maintenance of SAM database. The SAM database islocated under the registry HKLM\SAM\SAM, protected by ACL, andcan be opened using regedt32.exe

Book table editor and set the appropriate permissions to viewthe contents of SAM. The SAM database is stored on the disk inthe%systemroot%system32\conf ig\ directory

Recorded in the SAM file, in this directory also includes a

security file, the contents of the security database, there aremany relations between the two.

The SAM database contains information about all groups,accounts, including passwords, HASH, accounts, SID, and so on.These are described in detail later. Points to me

Case analysis of Chinese Win2K Adv Server.

Three 、 the structure of the SAM database in the registryExpand registry HKLM\SAM\SAM\:

H KLM---SAM

|---SAM

|---Domains

| |---Account

| | |---Aliases

| | | |---Members

| | | |---Nam e s

| | |---Group s

| | | |---00000201

| | | |---Nam e s

| | | |---None

| | |---Users

| | |---000001F4

| | |---000001F5

| | |---000003E8

| | |---000003E9

| | |---Names

| | |---Adaministrator| | |---Gu e s t

| | |---IU SR_REFDOM| | |---IWASM_REFDOM| |---Builtin

| |---Aliases

| | |---00000220

| | |---00000221

| | |---00000222

| | |---00000223

| | |---Me mbe r s

| | | |---S-1-5-21-1214440339-706699826-1708537768| | | |---000001 F4

| | | |---000001F5

| | | |---000003E8

| | | |---000003E9

| | |--- Name s

| | |---Administrators

| | |---Users

| | |---Gu e s t s

| | |---Power Users

| |---Groups

| | |---Names

| |

| |---Users

| |---Name s

|

|---RXA CT

This is the SAM tree in the registry on my machine.

Comparing the contents of the SAM file, you can see that theSAM tree in the registry is in fact the same as in the SAM file.However, the SAM file is listed first

RXACT then, in the Domains content (and so on) , the order ofexpression in the file is in reverse order with the tree orderin the registry. If used to seeing

File contents, from file 0000H to 0006Ch,

Indicates the location of the SAM database:

\systemroot\system32\conf ig\sam, but

The end is blank, until 01000h (hbin) , from here on, is thecontent of the entire database. The contents of the SAM databasefile are not included,

But it will be interspersed with the introduction, interestedin their own to study.

Four, SAM database structure and main content:

In the entire database, the main contents of the account existin the following locations:

Under \Domains\ is the SAM content in the domain (or local) ,with two branches, Account, and Builtin".

\Domains\Account is the user account content.

\Domains\Account\Users is the information of each account. Thesub key is the SID relative symbol of each account. Such as000001F4,

Each account has two sub items, F and V. Where \Names\ is theuser account name, each account name has only one default subkey,and the type in the item is not

Is the generic registry data type, but refers to the last item(relative identifier) of the SID that signs the account, suchas the Administrator under it,

The type is 0x1F4, so the 000001F4 from the front correspondsto the content of the account name administrator. This showsthe logic of MS account search.

Inference 1: from the registry structure to see the account,if you query an account name refdom related information, then,Microsoft from the account name refdom

Find its type, 0x3EB, and then find the relative sign (or SID)for the account content of 000003EB. All API functions (suchas NetUserEnum ())

That' s how it works. Therefore, if you change the type 0x3EBin the refdom account to 0x1F4, the account will be directedto the account of class 000001F4

Households. And this account 000001F4 is the administratoraccount, so that the system in the login process, the refdomaccount completely converted to administrator

Account, account refdom all content used, information isadminisrtator content, including passwords, permissions,desktop, records, access time and so on

Etc. . This inference should be true, but it will mean that twouser names correspond to one user' s information and that thereshould be an error in system startup!

The inference is that, in the previous analysis of the structure,the relationship between the account name and the SIDassociation was revealed during and after the login process.\Domains\Account\Users\000001F4, this is the accountinformation for administrator (other similar) . There are twosub items, V and F.

In the project V, the basic information of the account is kept,the user name, the user' s full name (full name) , the group, thedescription, the password, the hash, the annotation, and

whether it can be more

Change password, account enable, password setup time, etc. . Inthe project F, some login records are saved, such as the lastlogin time, the wrong login number, and so on

One important place is the SID relative symbol for this account.Before the analysis of the structure, did not pay attention tothis place, this is the idea put forward by Adam. This is wherethe SID relative sign is registered

An account in the table for two times, one is in the key of000001F4, another is the key content of F sub items, from fourbytes 48 to 51:

F4 010000, which is actually a long type variable, that is,000001 F4. When a flag appears in two places, it will happenSynchronization problem. Obviously, Microsoft has made themistake. The two variable should have been unified to mark auser account, but Microsoft played two variables separatelyBut there is no synchronization.

The 000001F4 in the subkey is used to correspond to the username administrator, which facilitates querying the accountinformation through the user, such as LookupAccountSid () andso on

The account related API function is used to locate user

friendhosting:(优惠55%)大促销,全场VPS降价55%,9个机房,不限流量

每年的7月的最后一个周五是全球性质的“系统管理员日”,据说是为了感谢系统管理员的辛苦工作....friendhosting决定从现在开始一直到9月8日对其全球9个数据中心的VPS进行4.5折(优惠55%)大促销。所有VPS基于KVM虚拟,给100M带宽,不限制流量,允许自定义上传ISO...官方网站:https://friendhosting.net比特币、信用卡、PayPal、支付宝、微信、we...

FlashFXP FTP工具无法连接主机常见原因及解决办法

目前,我们都在用哪个FTP软件?喜欢用的是WinSCP,是一款免费的FTP/SFTP软件。今天在帮助一个网友远程解决问题的时候看到他用的是FlashFXP FTP工具,这个工具以前我也用过,不过正版是需要付费的,但是网上有很多的绿色版本和破解版本。考虑到安全的问题,个人不建议选择破解版。但是这款软件还是比较好用的。今天主要是遇到他的虚拟主机无法通过FTP连接主机,这里我就帮忙看看到底是什么问题。一...

青云互联:香港安畅CN2弹性云限时首月五折,15元/月起,可选Windows/可自定义配置

青云互联怎么样?青云互联是一家成立于2020年的主机服务商,致力于为用户提供高性价比稳定快速的主机托管服务,目前提供有美国免费主机、香港主机、韩国服务器、香港服务器、美国云服务器,香港安畅cn2弹性云限时首月五折,15元/月起;可选Windows/可自定义配置,让您的网站高速、稳定运行。点击进入:青云互联官方网站地址青云互联优惠码:八折优惠码:ltY8sHMh (续费同价)青云互联香港云服务器活动...

帐号安全为你推荐
梦之队官网梦之队是什么呢?是那个国家的呢?他们又是参加那个项目的呢?得了几块金牌呢?丑福晋谁有好看的言情小说介绍下百花百游百花百游的五滴自游进程同一ip网站同IP的网站互相链接会被K吗?haole018.com为啥进WWWhaole001)COM怎么提示域名出错?囡道是haole001换地了吗www.baitu.com韩国片爱人.欲望的观看地址斗城网女追男有多易?喜欢你,可我不知道你喜不喜欢我!!平安夜希望有他陪我过5566.com请问如何创建网页(就是www.5566.com.cn这种格式的)鹤城勿扰非诚勿扰 怀化小伙 杨荣是哪一期www.niuniu.com哪里可以牛牛游戏在线玩?无聊就玩玩咯!
域名注册 到期域名查询 vps虚拟服务器 赵容 wdcp 好看的桌面背景大图 淘宝双十一2018 admit的用法 699美元 中国电信测网速 广州服务器 hktv 上海服务器 宏讯 web应用服务器 智能dns解析 监控服务器 数据库空间 云服务是什么意思 存储服务器 更多