Re: Calling 'NetUserChangePassword' for changing other user password



On Jul 17, 1:57 pm, Shlom <devsh...@xxxxxxxxx> wrote:
Hi,
I have user Target and Changer on domain (one of the following
servers: 2000,2003 and 2008)
In my program (C/C++), I perform a logon via the function
'WNetAddConnection2' with  user Changer user and then I call
'NetUserChangePassword' with the Target user...
This works fine, BUT:
I want to know how is it possible that even a limited user can do such
an operation (logon via 'WNetAddConnection2' and then change pass with
'NetUserChangePassword' for the target user)
In the MSDN it clearly says:
"The default ACL permits only Domain Admins and Account Operators to
call this function. On a member server or workstation, only
Administrators and Power Users can call this function."
=> how a limited user make this operation succeeded?

Pls let me know what you think.

I using a limited user.
but now I have a bigger issue - pls note:
In the MSDN for NetUserChangePassword there is a note:
"Windows NT: A server or domain can be configured to require a user
to log on before changing the password on a user account. In that
case, only members of the Administrators or Account Operators local
group or the user can change the password for a user account. If logon
is not required, a user can change the password for any user account,
as long as the user knows the current password."

This is the exact scenario I'm having.
I just want to know, why the MSDN specifies only win NT? Is it
possible that this is the behavior for other OS? where can I find a
documentation for that?

tx

.



Relevant Pages

  • Re: Problems with Domain Join for XPE FP2007
    ... If you logon to local account, are you able to get to domain resources using the same domain user account ... you can enable audit and logging on the server side and see why it is rejecting the client logon request. ... try to do a domain join, I'm getting various errors that prevent the ...
    (microsoft.public.windowsxp.embedded)
  • Re: Help with Security Audits
    ... Check to see if there is a local user account by that name on the server. ... When you say profile I don't ... > Successful Network Logon: ...
    (microsoft.public.win2000.security)
  • RE: Windows server 2003 Web Site
    ... Whats the chances of your server being Hack for lack of a better term? ... Logon ID: ... Target User Name: IUSR_DMZ ... Target Domain: DMZ ...
    (microsoft.public.windows.server.general)
  • Re: Error "the local policy of this system does not permit..
    ... only local users with Power User right can't logon ... it's not a server i'm using Windows XP with SP2. ... Give the user the right to logon. ... have to restrict this user account from having full access to the ...
    (microsoft.public.win2000.active_directory)
  • Re: Been hacked about 4 times now. Wanna be the 5th?
    ... it was my server I would rebuild the operating system from scratch. ... Logon attempt using explicit credentials: ... Target Domain: KINGSERVER2000 ... Caller User Name: KINGSERVER2000$ ...
    (microsoft.public.windows.server.security)