joeware - never stop exploring... :)

Information about joeware mixed with wild and crazy opinions...

Archive for posts by joe.

A Glimpse At Some AdMod Security Descriptor Fun…

by @ Monday, November 23rd, 2020. Filed under tech

So say you hate Account Operators group as much as I do and want to just strip the AO ACEs off of objects… Then this output below is something you will like… Less than 30 seconds to strip all AO access off of 20 objects remotely from a non-domain joined PC over wireless to a […]

Looking for the proper Holiday Ornament for this very tricky year?

by @ Sunday, November 22nd, 2020. Filed under general

Look no further, check out the custom ornament my niece put together just for 2020. https://www.etsy.com/shop/CustomDesignByBrooke ENJOY!    joe Rating 4.00 out of 5

9 out of 10 hackers prefer AdFind for AD Recon…

by @ Saturday, October 10th, 2020. Filed under general

https://thedfirreport.com/2020/10/08/ryuks-return/ This isn’t the first I have read about AdFind being used by bad actors, it won’t be the last. I first started hearing about AdFind being used in exploits and recon work roughly 2.5 or so years ago when IR teams and Security Researchers started emailing me about it and asking for hashes of […]

Beta version of AdMod and DACLs…

by @ Tuesday, August 18th, 2020. Filed under tech

Thoughts? [Tue 08/18/2020  0:24:46.40] E:\DEV\cpp\vs\AdMod\Debug>adfind -f ou=tobedeleted  -jsdenl AdFind V01.53.00cppBETA Joe Richards (support@joeware.net) July 2020 Using server: LO-DC4.lockout.test.loc:389 Directory: Windows Server 2019 (10.0.17134.1) Base DN: DC=lockout,DC=test,DC=loc dn:OU=tobedeleted,DC=lockout,DC=test,DC=loc [OWNER] LOCKOUT\Domain Admins [GROUP] LOCKOUT\Domain Admins [DACL] (FLAGS:INHERIT) [DACL] OBJ ALLOW;;[CR CHILD][DEL CHILD];inetOrgPerson;;BUILTIN\Account Operators [DACL] OBJ ALLOW;;[CR CHILD][DEL CHILD];computer;;BUILTIN\Account Operators [DACL] OBJ ALLOW;;[CR CHILD][DEL CHILD];group;;BUILTIN\Account Operators [DACL] OBJ […]

Clearing the DENY DELETE EVERYONE from OUs with AdFind|AdMod

by @ Thursday, July 9th, 2020. Filed under tech

Another common thing that people want to do from the command line with AdFind | AdMod is to clear the “Protect object from accidental deletion” setting that is implemented with a deny delete ACE on the object, specifically [DACL] DENY;;[DEL TREE][DEL];;;Everyone As mentioned previously, the Security Descriptor is a BLOB so you have to deal […]

How Do I Make an Object’s Security Descriptor Inheritable and also while I am at it… resetting from AdminSDHolder…

by @ Thursday, July 9th, 2020. Filed under tech

I recently received an email of: <SNIP> I have a bunch of previously sensitive&protected accounts where I like to enable inheritance.. Is it possible to remove protected inheritance flag with admod? <SNIP> The quick answer to the direct question is yes, there is an easy way to turn inheritance back on for an arbitrary object […]

Windows Server 2003 Support for AdFind??

by @ Sunday, February 9th, 2020. Filed under general, tech

Out of curiosity how many people need to run my tools on pre-Windows Server 2008 machines? I.E. Windows 2000, XP, 2003, etc? I was just alerted this last week by a random Russian user that AdFind doesn’t run ON Windows Server 2003 X64. I did some testing and that is correct, in fact it won’t […]

CVE-2020-0601–PATCH YOUR 2016/2019 DOMAIN CONTROLLERS!

by @ Wednesday, January 15th, 2020. Filed under tech

While Microsoft put a weak “important’ rating on CVE-2020-0601 the NSA (yes that NSA) has called it critical and severe. And since they found it, I am going to lay my bets with them. Microsoft’s bulletin says it is code signing issues, NSA and others in the social media circles says it is much deeper. […]

AdFind V01.52.00… Part Deux…

by @ Monday, January 13th, 2020. Filed under tech, updates

So try two… When I updated the web pages last night, I apparently updated a page that didn’t have the newer download mechanism in it so ended up breaking the download for AdFind. So you have gotten to experience a nice unhappy face page instead when trying to download. That was corrected a few hours […]

AdFind V01.52.00 released

by @ Sunday, January 12th, 2020. Filed under tech, updates

The latest version of AdFind, V01.52.00, is now released. You can find it at http://www.joeware.net/freetools/tools/adfind/ If the website shows V01.51.00 then use CTRL-F5 to update your local browser cache.   File information [Sat 01/11/2020 21:17:29.63]+ E:\DEV\cpp\vs\AdFind\Release>filever adfind.exe —– W32i   APP ENU     1.52.0.5064 shp  1,619,968 01-11-2020 adfind.exe [Sat 01/11/2020 21:17:40.58]+ E:\DEV\cpp\vs\AdFind\Release>adfind -appver AdFind V01.52.00cpp Joe Richards […]

[joeware – never stop exploring… :) is proudly powered by WordPress.]