Mastering Windows Network Forensics and Investigation, 2nd Edition
by Steven Anson, Steve Bunting, Ryan Johnson, Scott Pearson
Example Hack
Now that you have a good understanding of how Microsoft networks are structured, we’ll take a detailed look at how an attacker might exploit this structure to increase his control over the network. We will demonstrate how a hacker can use an exploit to break into a Windows 2008 Server, create a local user account on that server, and add that account to the Administrators group on that server. In this way, even if the administrator patches the vulnerability that the hacker used to compromise the box, the hacker will still have an account with administrator privileges on the server to gain access to the server at a later date.
The first problem that the hacker must address is how to initially compromise the system. In the real world, ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access