Templates for Groups

In an earlier post I had described how a hex editor can be used to enumerate the members of a group out of the security manager's database. By request of a reader I now release the complete template for the 010 Editor.

Beside the template the package also contains two include files. SID.inc.bt defines a structure that is needed in order to display Security IDs. It is based on a blog post by Raymond Chen.

The second include file, SD.inc.bt, builds thereupon and defines some structures for Security Descriptors (SD). For the sake of simplicity it is limited to the self-relative form of a SD. Some background information regarding the inheritance of the Access Control Entries (ACE) in a SD are available from article no. 188 760 of the Microsoft Knowledge Base.

Archives

Imprint

This blog is a project of:
Andreas Schuster
Im Äuelchen 45
D-53177 Bonn
impressum@forensikblog.de

Copyright © 2005-2012 by
Andreas Schuster
All rights reserved.
Powered by Movable Type 5.12