Microsoft Windows SMB LsaQueryInformationPolicy Function NULL Session Domain SID Enumeration

This script is Copyright (C) 2000-2016 Tenable Network Security, Inc.


Synopsis :

It was possible to obtain the domain SID.

Description :

By emulating the call to LsaQueryInformationPolicy(), it was possible
to obtain the domain SID (Security Identifier).

The domain SID can then be used to get the list of users of the
domain.

Solution :

n/a

Risk factor :

None

Family: Windows

Nessus Plugin ID: 10398 ()

Bugtraq ID: 959

CVE ID: CVE-2000-1200

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now