|
771 | 771 | "microsoft-ds" |
772 | 772 | ], |
773 | 773 | "targets": null, |
774 | | - "mod_time": "2024-04-26 12:33:43 +0000", |
| 774 | + "mod_time": "2024-11-12 12:08:18 +0000", |
775 | 775 | "path": "/modules/auxiliary/admin/dcerpc/cve_2022_26923_certifried.rb", |
776 | 776 | "is_install_path": true, |
777 | 777 | "ref_name": "admin/dcerpc/cve_2022_26923_certifried", |
|
874 | 874 | } |
875 | 875 | ] |
876 | 876 | }, |
877 | | - "auxiliary_admin/dcerpc/samr_computer": { |
878 | | - "name": "SAMR Computer Management", |
879 | | - "fullname": "auxiliary/admin/dcerpc/samr_computer", |
| 877 | + "auxiliary_admin/dcerpc/samr_account": { |
| 878 | + "name": "SAMR Account Management", |
| 879 | + "fullname": "auxiliary/admin/dcerpc/samr_account", |
880 | 880 | "aliases": [ |
881 | | - |
| 881 | + "auxiliary/admin/dcerpc/samr_computer" |
882 | 882 | ], |
883 | 883 | "rank": 300, |
884 | 884 | "disclosure_date": null, |
885 | 885 | "type": "auxiliary", |
886 | 886 | "author": [ |
887 | 887 | "JaGoTu", |
888 | | - "Spencer McIntyre" |
| 888 | + "Spencer McIntyre", |
| 889 | + "smashery" |
889 | 890 | ], |
890 | | - "description": "Add, lookup and delete computer / machine accounts via MS-SAMR. By default\n standard active directory users can add up to 10 new computers to the\n domain. Administrative privileges however are required to delete the\n created accounts.", |
| 891 | + "description": "Add, lookup and delete user / machine accounts via MS-SAMR. By default\n standard active directory users can add up to 10 new computers to the\n domain (MachineAccountQuota). Administrative privileges however are required\n to delete the created accounts, or to create/delete user accounts.", |
891 | 892 | "references": [ |
892 | 893 | "URL-https://github.com/SecureAuthCorp/impacket/blob/master/examples/addcomputer.py" |
893 | 894 | ], |
|
903 | 904 | "microsoft-ds" |
904 | 905 | ], |
905 | 906 | "targets": null, |
906 | | - "mod_time": "2024-04-16 16:43:30 +0000", |
907 | | - "path": "/modules/auxiliary/admin/dcerpc/samr_computer.rb", |
| 907 | + "mod_time": "2024-12-09 08:49:04 +0000", |
| 908 | + "path": "/modules/auxiliary/admin/dcerpc/samr_account.rb", |
908 | 909 | "is_install_path": true, |
909 | | - "ref_name": "admin/dcerpc/samr_computer", |
| 910 | + "ref_name": "admin/dcerpc/samr_account", |
910 | 911 | "check": false, |
911 | 912 | "post_auth": false, |
912 | 913 | "default_credential": false, |
|
919 | 920 | ], |
920 | 921 | "SideEffects": [ |
921 | 922 | "ioc-in-logs" |
| 923 | + ], |
| 924 | + "AKA": [ |
| 925 | + "samr_computer", |
| 926 | + "samr_user" |
922 | 927 | ] |
923 | 928 | }, |
924 | 929 | "session_types": [ |
|
931 | 936 | "description": "Add a computer account" |
932 | 937 | }, |
933 | 938 | { |
934 | | - "name": "DELETE_COMPUTER", |
935 | | - "description": "Delete a computer account" |
| 939 | + "name": "ADD_USER", |
| 940 | + "description": "Add a user account" |
| 941 | + }, |
| 942 | + { |
| 943 | + "name": "DELETE_ACCOUNT", |
| 944 | + "description": "Delete a computer or user account" |
936 | 945 | }, |
937 | 946 | { |
938 | | - "name": "LOOKUP_COMPUTER", |
939 | | - "description": "Lookup a computer account" |
| 947 | + "name": "LOOKUP_ACCOUNT", |
| 948 | + "description": "Lookup a computer or user account" |
940 | 949 | } |
941 | 950 | ] |
942 | 951 | }, |
|
0 commit comments