專案資訊 #1074
進行中專案資訊 #1064: 2025-PenTest
Use of ""Pre-Windows 2000 Compatible Access
100%
概述
N bookmark2025052801463337292181788 "Use of ""Pre-Windows 2000 Compatible Access"" group
" "The “Pre-Windows 2000 Compatible Access” group allows its members read access to all user and computer objects in Active Directory, which can expose sensitive information. If an attacker gains membership in this group, they can exploit these permissions to gather valuable data and potentially elevate their privileges, compromising the security of the entire network.
" "Remove ""Anonymous Logon"" from the ""Pre-Windows 2000 Compatible Access"" group.
The Builtin\Pre-Windows 2000 Compatible Access group was originally designed to ensure backward compatibility for systems that predate Windows 2000 (Windows NT 4.0). It is imperative that this group exclusively encompass Authenticated Users (S-1-5-11). ADCS servers are automatically added to this group upon installation. Review any other membership to ensure that there is a business purpose of maintaining the membership. Should it not be necessary anymore, consider removing the membership."
檔案
是由 益利 周 於 約 2 個月 前更新
- 檔案 clipboard-202511271719-cigab.png clipboard-202511271719-cigab.png 已新增
- 狀態 從 New-新增 變更為 Resolved-解决
- 完成百分比 從 0 變更為 100
於 Pre-Windows 2000 Compatible Access 群組中
移除 "Anonymous Logon"

名單中已無 Anonymous Logon