Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 6th, 2011, 12:42 AM
MacQibble MacQibble is offline
Infrequent Poster
 
Join Date: Jan 2011
Posts: 28
Default S-1-5-21-Domain-500 question

Hi.
Please know I'm not expecting to be offered one-on-one tuition, but I'll take any advice I can get to learn. (Can't seem to find an obvious home for this stuff apart from here on Wilders).

Per MrBrian and Wilders, have discovered the hidden fruits of AccessChk and AccessEnum.

AccessEnum has thrown up many questions, but the most intriguing are four entries under 'C:\Windows\Performance\WinSAT' showing

"Account Unknown(S-1-5-21-{X-Y-Z}-500)" with full control over some ShaderCache files.

(I'm so paranoid i changed the actual numbers!)

I know (I think) that WinSAT measures system's performance and capabilities and gives the WEI score. I've disabled this task. The folder also contains some WMP videos that came with the system. All seems tame enough to me.

Thing is ... my understanding of S-1-5-21-Domain-500 is that it's the real Administrator and .. erm ... this SID certainly isn't my Real Administrator as listed in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList.

The domain for the above is different to my three self-created accounts for Real Admin, Admin, and Standard user. I don't use the Real Admin. I only enabled it and gave it a pretty hefty strong password for belt and braces.

So ... just wondering if I should be panicking? Right now I'd feel more stupid not asking.
  #2  
Old March 6th, 2011, 01:50 AM
Sully Sully is offline
Massive Poster
 
Join Date: Dec 2005
Posts: 3,696
Default Re: S-1-5-21-Domain-500 question

I am not sure exactly what you are asking. No problem though. That string you gave is part of the registry and part of .inf file syntax. The identifiers there are global identifiers, every computer might use one or another of them.

The specific part that you fear to publish is unique as well, and unless someone crafts an exploit for you and that ID specifically, not much can be done with it. Besides that, if they do get the ID of a registry key, they still have to know the password.

If you want to know more about that ID string and why it is such, how to use it, where it lives, you need to check out some Security Template information, especially on w2k and xp. There are a number of really good sites out there that will break down the .inf syntax in a security template. As it so happens, you used a security template when you installed the OS, usually defltwks.inf. You can examine that, and once you begin to comprehend the madness of .inf syntax, you can see exactly what rights are placed for objects and containers that are there on a default install, you can see the inheritance they give or get and why that effects things, and you can also see those GUIDs like the one you mentioned, and see how they play into the mix.

This is hardcore geek land you are entering. Not a great abundance of information in one place, but scattered in many. I have gone to this land many times, and never have found the holy grail, only pieces along the way. I will tell you this though, if you can read a security template, you will gain a heaping amount of insight into how everything is restricted.

Sul.
__________________
I do things TO my computer, not WITH my computer.. I am a nerd.
  #3  
Old March 6th, 2011, 08:08 AM
katio
 
Posts: n/a
Default Re: S-1-5-21-Domain-500 question

Same here, nothing out of ordinary.

Theory: It's whatever user is on the DVD installer which runs the performance check prior you setting up any user accounts.

Last edited by katio : March 6th, 2011 at 08:19 AM.
  #4  
Old March 6th, 2011, 01:23 PM
MacQibble MacQibble is offline
Infrequent Poster
 
Join Date: Jan 2011
Posts: 28
Default Re: S-1-5-21-Domain-500 question

Quote:
Originally Posted by Sully
This is hardcore geek land you are entering

Two adages applies: A little knowledge is a dangerouis thing / Fools go where angels fear to tread

Thanks for invaluable insights. By way of explanation for panic, found this article on "Well-known SIDs":

http://support.microsoft.com/kb/243330

Quote:

SID: S-1-5-21-domain-500
Name: Administrator
Description: A user account for the system administrator. By default, it is the only user account that is given full control

Misread and assumed I should only find one

Given katio's post, logical that the installation process, prior to any user admin account set up, has to have full control. That'll do for me.

Cheers

Last edited by MacQibble : March 6th, 2011 at 01:31 PM.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:16 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums