-

 -

11:23 10.11.2017
: 5

 -

   imkort

 - e-mail

 

 -

 LiveInternet.ru:
: 18.08.2015
: 36
: 3
: 42

:

(0)

DCOM

, 27 2017 . 00:20 +
windows-macos-1.ucoz.ru/pub...63-1-0-270

:

  1. DCOM 10016
  2. SLSID {1F87137D-0E7C-44d5-8C73-4EFFB68962F2}, C:\Windows\system32\wbem\wmiprvse.exe, Microsoft WMI Provider Subsystem Secured Host AppID, \\HKEY_CLASSES_ROOT|AppID. ?
  3. dcom {1F87137D-0E7C-44d5-8C73-4EFFB68962F2} appid
  4. dcom wmiprvse appid
  5. EventID - : 10016, : DCOM

SLSID {1F87137D-0E7C-44d5-8C73-4EFFB68962F2},  C:\Windows\system32\wbem\wmiprvse.exe,  Microsoft WMI Provider Subsystem Secured Host   AppID,     \\HKEY_CLASSES_ROOT|AppID.  ?

Win+R dcomcnfg.exe

, .

:

HKEY_CLASSES_ROOT\AppID\

, , - {1F87137D-0E7C-44d5-8C73-4EFFB68962F2}.

:


, .
, .

.
, , .

System.

, System.

   system

:

Network Service


: .

- .
- . .

HKEY_CLASSES_ROOT\CLSID\

:
HKEY_CLASSES_ROOT\AppID\
{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}
HKEY_CLASSES_ROOT\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}

Powershell:

New-PSDrive -PSProvider registry -Root HKEY_CLASSES_ROOT -Name HKCR

Get-Acl "HKCR:\CLSID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}"  | Format-List

Get-Acl "HKCR:\AppID\{73E709EA-5D93-4B2E-BBB0-99B7938DA9E4}"  | Format-List

Group: NT AUTHORITY\SYSTEM, - .

Path   : Microsoft.PowerShell.Core\Registry::HKEY_CLASSES_ROOT\CLSID\{73E709EA-
         5D93-4B2E-BBB0-99B7938DA9E4}
Owner  : BUILTIN\
Group  : NT AUTHORITY\SYSTEM
Access : BUILTIN\ Allow  ReadKey
         BUILTIN\ Allow  -2147483648
         BUILTIN\ Allow  SetValue, CreateSubKey, Delete, Re
         adKey
         BUILTIN\ Allow  -1073676288
         BUILTIN\ Allow  FullControl
         BUILTIN\ Allow  268435456
         NT AUTHORITY\SYSTEM Allow  FullControl
         NT AUTHORITY\SYSTEM Allow  268435456
         - Allow  268435456
Audit  :
Sddl   : O:BAG:SYD:AI(A;ID;KR;;;BU)(A;CIIOID;GR;;;BU)(A;ID;CCDCLCSWRPSDRC;;;PU)
         (A;CIIOID;SDGWGR;;;PU)(A;ID;KA;;;BA)(A;CIIOID;GA;;;BA)(A;ID;KA;;;SY)(A
         ;CIIOID;GA;;;SY)(A;CIIOID;GA;;;CO)

?

NT AUTHORITY\SYSTEM
NT AUTHORITY\SYSTEM , - .
, - .

?

SubinACL - System32.

1) BAT- permission .bat

subinacl.exe /noverbose /outputlog=test.txt /subkeyreg "HKEY_CLASSES_ROOT\AppID\{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}"
pause

{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}, " " PERMISSION .

test.txt

2)  test.txt .

=======================================================================
+KeyReg HKEY_CLASSES_ROOT\AppID\{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}
=======================================================================
/control=0x1400
/owner             =builtin\
/primary group     =system
/audit ace count   =0
/perm. ace count   =5
/pace =system  Type=0x0 Flags=0x2 AccessMask=0xf003f
/pace =builtin\  Type=0x0 Flags=0x2 AccessMask=0xf003f
/pace =  Type=0x0 Flags=0x2 AccessMask=0x20019
/pace =builtin\   Type=0x0 Flags=0x2 AccessMask=0xf003f
/pace =builtin\  Type=0x0 Flags=0x2 AccessMask=0xf003f

primary group     =system(NT AUTHORITY) TrustedInstaller(NT SERVICE), .

3) BAT- permission .bat

subinacl.exe /playfile test.txt /subkeyreg "HKEY_CLASSES_ROOT\CLSID\{1F87137D-0E7C-44d5-8C73-4EFFB68962F2}"
pause

{1F87137D-0E7C-44d5-8C73-4EFFB68962F2} , .

4) BAT- permission .bat

- permission .bat:

subinacl.exe /outputlog=description.txt /subkeyreg "HKEY_CLASSES_ROOT\AppID\{1F87137D-0E7C-44d5-8C73-4EFFB68962F2}"
pause

 {1F87137D-0E7C-44d5-8C73-4EFFB68962F2} .

, AkelPad - 866 (OEM-) :

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Console]
"CodePage"=dword:00000362

[HKEY_CURRENT_USER\Console\ConEmu]
"FaceName"="Lucida Console"

permission


,


.

?

, :

subinacl.exe /noverbose /outputlog=test.txt /subkeyreg "HKEY_CLASSES_ROOT\AppID"
pause

, test.txt .
control=0x400   control=0x1400 Flags= Flags=0x0.
"control=0x400" "control=0x1400"
,
. 3). <> <>.

Permission.
, , 10000 .


CLSID {1F87137D-0E7C-44d5-8C73-4EFFB68962F2}

  • , " " -
    {1F87137D-0E7C-44d5-8C73-4EFFB68962F2}
  • :
    HKEY_CLASSES_ROOT\CLSID\{1F87137D-0E7C-44d5-8C73-4EFFB68962F2}
  • !
  • %windir%\SYSTEM32\dcomcnfg.exe
  • DCOM , .

:  
(0)

, 10 2017 . 10:55 +
windows-macos-1.ucoz.ru/pub...63-1-0-220

, , . 100% , , "" - .

, . , .

, .
.
, .

:

  • System Windows.
  • , SHIFT+F10, .
  • regedit .

HKEY_LOCAL_MACHINE .

  • system Windows D:\Windows\System32\config , 123.
  • 123 Setup
  • CmdLine cmd.exe
  • SetupType 2

 

, :


  •  

net localgroup /add

, , " "

  • exit

, lusrmgr.msc .

 2 (700x700, 218Kb)

" ":
Windows .
1 -
2 - -
3 - WMI - 0x8007050a


:  

 : [1]