January 2006
Beginner
832 pages
27h 52m
English
A good example of a useful real-world task is when you are curious to see what ACEs have been set on an object, such as a domain or Organizational Unit. Example 26-4 is a piece of code that can be used as the basis for checking through an Active Directory forest looking for irregularities or be used to help you build the proper values for your own delegation script. The code is fairly simple but very long, due to the fact that it has to check every constant for both the SACL and DACL of each object.
Example 26-4. Examining the security descriptor of an object
'**************************************************************************** 'Script to list SecurityDescriptor for specified Active Directory Object 'Run script with cscript - cscript sdlist.vbs '**************************************************************************** Option Explicit '**************************************************************************** 'Declare the variables '**************************************************************************** Dim objObject, objRootDSE, objSchema, objExtRights, objEnum, objSD Dim objDACL, objSACL, objACE Dim SchemaGuids, CARGuids, SDCtlD, AccMaskD, ACEFlagsD, FlagsD Dim strDC, strSchemaPath, strConfigPath, strGUID, strLDAPPath '**************************************************************************** 'AccessMask constants '**************************************************************************** Const FULL_CONTROL = ...
Read now
Unlock full access