NW Hack
NW Hack
NW Hack
NW-HACK
(thank you)
������������������������������������������������������������������������������
SYNTAX:
NW-HACK <Enter>
~ Select Lock File Server Console from the NetWare v3.x MONITOR.NLM
main menu. This will password-protect the server console.
BUT any of this CAN'T protect from NW-HACK to make security hole is your novell
server. When NW-HACK running on one network Workstation it could pretend to be
another user currently signed onto the same file server (SUPERVISOR).
If you execute this program on the USER Workstation it will make ALL USERS
an account with supervisor privledges. I will give a quick and easy rundown
on how to use this program. First thing put it on a floppy diskette.
Of course, there are some variables in the command line. If the diskette
drive is b, than change the command line to "B:NW-HACK"
TO PROTECT YOUR NEW Supervisor privledges from being remove: NOW is the best
time to use "SUPER.EXE".....
"SUPER -" will modify the security byte of your bindery property SECURITY_EQUALS
(can only be done by somebody with supervisor equivalence) to 0x22
(read/write object). This allows the user to change his/her own
security equivalences. (!!!)
NO ONE CAN CHANGE THIS SECURITY HOLE (EVEN THE SUPERVISOR !!!. TO REMOVE
THIS HOLE THER IS A NEED TO DELETE YOU FROM SERVER NAME LIST AND RE INSTALL
YOU (& breathing down your neck)...
v1.0 Aug 92: - Allow to run SUPER against another user's account.
Sep 92: - Allow to run BATCH files and internal DOS commands
- Output redirectable with DOS pipes
v2.0 Dec 93: - Adapt to NetWare v3.12 (and a little to v4.0x)
Available options:
? Display this help screen
<none> Display current security status
- Remove supervisor equivalence, enable SUPER
+ Make user equivalent to supervisor
# Remove supervisor equivalence and disable SUPER
* Grant supervisor equivalence and disable SUPER
<cmd> Execute any command as supervisor (NW 386 only)
Background:
SUPER allows a user who in Supervisor equivalent to do the
daily work as normal user, while Supervisor equivalence is
available when needed. This reduces the risk of accidental
damage to files caused by carelessness, unattended
workstations, or viruses.
Since the user may change the equivalences now, he/she can
later add Supervisor equivalence with "SUPER +" when needed.
"SUPER <command>" will first add Supervisor equivalence,
then execute the command, and finally remove Supervisor
equivalence.
BINDFIX warns:
'Warning: Object <name> property SECURITY_EQUALS has incorrect
security flags.'
"SUPER -" will modify the security byte of your bindery property
SECURITY_EQUALS to 0x22 (read/write object). This allows the user
to change his/her own security equivalences.
SOLUTION
SUPER has parameters that allow resetting the bindery flag to it's
original state - obviously this will prevent these users from
receiving SV equivalence with SUPER.