[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fMzRt4-YVCi794Oy1k9kH42FsW7gsSykFn8Ta2SkbouQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},896,"How can an attacker perform RID hijacking on a Windows system?","First, the attacker must obtain SYSTEM privileges. Then they navigate to `HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users` and locate the registry key corresponding to the low-privilege account (e.g., `000003E9` for RID 1001). They edit the F key, setting the little-endian values at offsets 0x30f and 0x31f to the hexadecimal representation of the target RID (e.g., `01F4` for the built-in Administrator RID 500). After logging out and back in, the account inherits the target's privileges. The [Metasploit module `windows\u002Fmanage\u002Frid_hijack`](https:\u002F\u002Fwww.rapid7.com\u002Fdb\u002Fmodules\u002Fpost\u002Fwindows\u002Fmanage\u002Frid_hijack\u002F) automates this process.","\u003Cp>First, the attacker must obtain SYSTEM privileges. Then they navigate to `HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users` and locate the registry key corresponding to the low-privilege account (e.g., `000003E9` for RID 1001). They edit the F key, setting the little-endian values at offsets 0x30f and 0x31f to the hexadecimal representation of the target RID (e.g., `01F4` for the built-in Administrator RID 500). After logging out and back in, the account inherits the target&#39;s privileges. The [Metasploit module `windows\u002Fmanage\u002Frid_hijack`](https:\u002F\u002Fwww.rapid7.com\u002Fdb\u002Fmodules\u002Fpost\u002Fwindows\u002Fmanage\u002Frid_hijack\u002F) automates this process.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-rid-hijacking-of-windows-accounts\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-perform-rid-hijacking-on-a-windows-system-1777481408564","RID hijacking, registry editing, SYSTEM privileges, Metasploit, Windows security",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},218,"Penetration Techniques - RID Hijacking of Windows Accounts","penetration-techniques-rid-hijacking-of-windows-accounts","Learn how RID hijacking exploits Windows registry to escalate account privileges by modifying RID values, enabling unauthorized admin access.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Penetration Techniques - Account Hiding in Windows Systems\", we introduced the technique of creating hidden accounts through account cloning by copying the F key value from the target account's corresponding registry entry, allowing the hidden account to gain identical permissions.\u003C\u002Fp>\u003Cp>If we consider an alternative approach—overwriting part of the content of the F key in the target account's corresponding registry entry onto an existing account—can the existing account then acquire the target account's permissions?\u003C\u002Fp>\u003Cp>This is the method to be introduced in this article—RID Hijacking.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was first publicly disclosed in December 2017 at the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fcsl.com.co\u002Frid-hijacking\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods of RID Hijacking\u003C\u002Fli>\u003Cli>Implementation approach for script writing\u003C\u002Fli>\u003Cli>Exploitation analysis\u003C\u002Fli>\u003Cli>Defense Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Related Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>SID\u003C\u002Fh3>\u003Cp>Full name: Security Identifiers, a variable-length structure used by the Windows system to uniquely identify users or groups\u003C\u002Fp>\u003Cp>Official documentation address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002F\u002Flibrary\u002Fwindows\u002Fdesktop\u002Faa379594(v=vs.85).aspx\u003C\u002Fp>\u003Cp>SID contains the following information:\u003C\u002Fp>\u003Cul>\u003Cli>The revision level of the SID structure\u003C\u002Fli>\u003Cli>48-bit identifier authority value\u003C\u002Fli>\u003Cli>relative identifier (RID)\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Example\u003C\u002Fh4>\u003Cp>Execute 'whoami \u002Fall' in the Windows command line to obtain the current user's SID, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017331423_0_6c99d3caf1.jpeg\">\u003C\u002Fp>\u003Cp>SID is: S-1-5-21-2752016420-1571072424-526487797-1001\u003C\u002Fp>\u003Cp>S indicates that the string is an SID\u003C\u002Fp>\u003Cp>1 indicates the version number of the SID\u003C\u002Fp>\u003Cp>5-21-2752016420-1571072424-526487797 corresponds to the ID authority\u003C\u002Fp>\u003Cp>1001 indicates the RID\u003C\u002Fp>\u003Ch3>RID\u003C\u002Fh3>\u003Cp>Windows system accounts correspond to fixed RIDs:\u003C\u002Fp>\u003Cul>\u003Cli>500: ADMINISTRATOR\u003C\u002Fli>\u003Cli>501: GUEST\u003C\u002Fli>\u003Cli>502: krbtgt (domain environment)\u003C\u002Fli>\u003Cli>512: Domain Admins (domain environment)\u003C\u002Fli>\u003Cli>513: Domain Users (domain environment)\u003C\u002Fli>\u003Cli>514: Domain Guests (domain environment)\u003C\u002Fli>\u003Cli>515: Domain Computers (domain environment)\u003C\u002Fli>\u003Cli>516: Domain Controllers (domain environment)\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 RID hijacking method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For Windows systems, the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names contains a list of all accounts in the current system. The default value of each account corresponds to the registry location of that account's detailed information (i.e., the hexadecimal representation of the RID).\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>System privileges are required to read this information.\u003C\u002Fp>\u003Cp>Example as shown in the figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017381850_1_593b9d869d.jpeg\">\u003C\u002Fp>\u003Cp>The default registry value for account a is 0x3e9.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a has standard user privileges.\u003C\u002Fp>\u003Cp>The registry location for detailed information is HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003E9.\u003C\u002Fp>\u003Cp>Detailed information is shown in the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017403997_2_fc28a21357.jpeg\">\u003C\u002Fp>\u003Cp>The content of the F key is shown in the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017452879_3_c1e3d41263.jpeg\">\u003C\u002Fp>\u003Cp>Offset positions 0x30f and 0x31f correspond to the RID.\u003C\u002Fp>\u003Cp>Due to little-endian byte storage, the RID value obtained from the F key in the above figure is 0x03E9, which converts to decimal 1001.\u003C\u002Fp>\u003Cp>Log in with account a, execute whoami \u002Fall to obtain the SID of account a, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017470986_4_b20545abd6.jpeg\">\u003C\u002Fp>\u003Cp>Same content\u003C\u002Fp>\u003Ch3>Test 1: Impersonating the built-in administrator account ADMINISTRATOR\u003C\u002Fh3>\u003Cp>Modify the RID of account a to 500 (fixed value, representing the Windows system built-in administrator ADMINISTRATOR), corresponding to hexadecimal 01F4, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017483291_5_6bd856f92e.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a needs to log in again to take effect.\u003C\u002Fp>\u003Cp>Log in to account a, account a inherits the permissions of ADMINISTRATOR and becomes an administrator.\u003C\u002Fp>\u003Cp>The login username is: original username.machine name, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017494159_6_858d5f069e.jpeg\">\u003C\u002Fp>\u003Cp>The user folder also changes accordingly, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017502770_7_612e452bd2.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive understanding:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a changed to new account a.WIN-BH7SVRRDGVA, inheriting ADMINISTRATOR privileges\u003C\u002Fp>\u003Ch3>Test 2: Impersonating administrator account 1\u003C\u002Fh3>\u003Cp>Created new administrator account 1 with RID 1000 (0x03e8), as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017508666_8_610e4f3946.jpeg\">\u003C\u002Fp>\u003Cp>Modified the RID of account a to 1000 (0x03e8)\u003C\u002Fp>\u003Cp>After modification, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017515207_9_4dd5a7c525.jpeg\">\u003C\u002Fp>\u003Cp>Logged back into account a\u003C\u002Fp>\u003Cp>Account a inherited the privileges of account 1 and became an administrator\u003C\u002Fp>\u003Cp>The login username changed to 1, while executing whoami \u002Fall shows the username as a, but with RID 1000 (account 1's RID), as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017519939_10_bf0a37fbdb.jpeg\">\u003C\u002Fp>\u003Cp>Environment variables correspond to user 1, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017523448_11_8436753d5d.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive understanding:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a transformed into the original account 1, inheriting its privileges, but retains the display of account a in some functions\u003C\u002Fp>\u003Ch2>0x04 Implementation Approach for Script Writing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Implementation Approach\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SYSTEM privileges\u003C\u002Fli>\u003Cli>Read registry information of the specified account\u003C\u002Fli>\u003Cli>Modify the fixed offset address, specifying it as the new RID\u003C\u002Fli>\u003Cli>Import the registry to complete the modification\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For specific implementation details, refer to the instructions in the article 'Penetration Techniques – Account Hiding in Windows Systems'\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Since the functionality is relatively simple, the implementation code is left for the reader to complete\u003C\u002Fp>\u003Cp>Corresponding Metasploit module: windows\u002Fmanage\u002Frid_hijack\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For RID Hijacking, the implementation principle is straightforward:\u003Cstrong>Locate the registry file of the account and modify the location representing the RID information.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>However, the following shortcomings exist in its exploitation:\u003C\u002Fp>\u003Cul>\u003Cli>The account must be logged in again to take effect.\u003C\u002Fli>\u003Cli>Environment variables are modified, affecting normal usage.\u003C\u002Fli>\u003Cli>The display of the username has issues and is easily detectable.\u003C\u002Fli>\u003Cli>Simulating ADMINISTRATOR privileges will create a new user folder.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Exploitation Scenarios\u003C\u002Fh3>\u003Col>\u003Cli>Enable the guest account, modify the RID, log in to the guest account to obtain high privileges.\u003C\u002Fli>\u003Cli>Modify the RID of a low-privilege user and log in to gain high privileges.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, the attacker first needs to obtain system privileges on the current system.\u003C\u002Fp>\u003Cp>Detection Approach:\u003C\u002Fp>\u003Cul>\u003Cli>Check if there are any anomalies in the information under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\.\u003C\u002Fli>\u003Cli>Check if the guest account has been enabled.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation method of RID Hijacking, analyzes the exploitation conditions, and provides defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article \"Penetration Techniques - Account Hiding in Windows Systems\", we introduced the technique of creating hidden accounts through account cloning by copying the F key value from the target account's corresponding registry entry, allowing the hidden account to gain identical permissions.\u003C\u002Fp>\u003Cp>If we consider an alternative approach—overwriting part of the content of the F key in the target account's corresponding registry entry onto an existing account—can the existing account then acquire the target account's permissions?\u003C\u002Fp>\u003Cp>This is the method to be introduced in this article—RID Hijacking.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This method was first publicly disclosed in December 2017 at the following address:\u003C\u002Fp>\u003Cp>http:\u002F\u002Fcsl.com.co\u002Frid-hijacking\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods of RID Hijacking\u003C\u002Fli>\u003Cli>Implementation approach for script writing\u003C\u002Fli>\u003Cli>Exploitation analysis\u003C\u002Fli>\u003Cli>Defense Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Related Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>SID\u003C\u002Fh3>\u003Cp>Full name: Security Identifiers, a variable-length structure used by the Windows system to uniquely identify users or groups\u003C\u002Fp>\u003Cp>Official documentation address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002F\u002Flibrary\u002Fwindows\u002Fdesktop\u002Faa379594(v=vs.85).aspx\u003C\u002Fp>\u003Cp>SID contains the following information:\u003C\u002Fp>\u003Cul>\u003Cli>The revision level of the SID structure\u003C\u002Fli>\u003Cli>48-bit identifier authority value\u003C\u002Fli>\u003Cli>relative identifier (RID)\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>Example\u003C\u002Fh4>\u003Cp>Execute 'whoami \u002Fall' in the Windows command line to obtain the current user's SID, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017331423_0_6c99d3caf1-1.jpeg\">\u003C\u002Fp>\u003Cp>SID is: S-1-5-21-2752016420-1571072424-526487797-1001\u003C\u002Fp>\u003Cp>S indicates that the string is an SID\u003C\u002Fp>\u003Cp>1 indicates the version number of the SID\u003C\u002Fp>\u003Cp>5-21-2752016420-1571072424-526487797 corresponds to the ID authority\u003C\u002Fp>\u003Cp>1001 indicates the RID\u003C\u002Fp>\u003Ch3>RID\u003C\u002Fh3>\u003Cp>Windows system accounts correspond to fixed RIDs:\u003C\u002Fp>\u003Cul>\u003Cli>500: ADMINISTRATOR\u003C\u002Fli>\u003Cli>501: GUEST\u003C\u002Fli>\u003Cli>502: krbtgt (domain environment)\u003C\u002Fli>\u003Cli>512: Domain Admins (domain environment)\u003C\u002Fli>\u003Cli>513: Domain Users (domain environment)\u003C\u002Fli>\u003Cli>514: Domain Guests (domain environment)\u003C\u002Fli>\u003Cli>515: Domain Computers (domain environment)\u003C\u002Fli>\u003Cli>516: Domain Controllers (domain environment)\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 RID hijacking method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For Windows systems, the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names contains a list of all accounts in the current system. The default value of each account corresponds to the registry location of that account's detailed information (i.e., the hexadecimal representation of the RID).\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>System privileges are required to read this information.\u003C\u002Fp>\u003Cp>Example as shown in the figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017381850_1_593b9d869d-1.jpeg\">\u003C\u002Fp>\u003Cp>The default registry value for account a is 0x3e9.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a has standard user privileges.\u003C\u002Fp>\u003Cp>The registry location for detailed information is HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003E9.\u003C\u002Fp>\u003Cp>Detailed information is shown in the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017403997_2_fc28a21357-1.jpeg\">\u003C\u002Fp>\u003Cp>The content of the F key is shown in the figure below:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017452879_3_c1e3d41263-1.jpeg\">\u003C\u002Fp>\u003Cp>Offset positions 0x30f and 0x31f correspond to the RID.\u003C\u002Fp>\u003Cp>Due to little-endian byte storage, the RID value obtained from the F key in the above figure is 0x03E9, which converts to decimal 1001.\u003C\u002Fp>\u003Cp>Log in with account a, execute whoami \u002Fall to obtain the SID of account a, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017470986_4_b20545abd6-1.jpeg\">\u003C\u002Fp>\u003Cp>Same content\u003C\u002Fp>\u003Ch3>Test 1: Impersonating the built-in administrator account ADMINISTRATOR\u003C\u002Fh3>\u003Cp>Modify the RID of account a to 500 (fixed value, representing the Windows system built-in administrator ADMINISTRATOR), corresponding to hexadecimal 01F4, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017483291_5_6bd856f92e-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a needs to log in again to take effect.\u003C\u002Fp>\u003Cp>Log in to account a, account a inherits the permissions of ADMINISTRATOR and becomes an administrator.\u003C\u002Fp>\u003Cp>The login username is: original username.machine name, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017494159_6_858d5f069e-1.jpeg\">\u003C\u002Fp>\u003Cp>The user folder also changes accordingly, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017502770_7_612e452bd2-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive understanding:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a changed to new account a.WIN-BH7SVRRDGVA, inheriting ADMINISTRATOR privileges\u003C\u002Fp>\u003Ch3>Test 2: Impersonating administrator account 1\u003C\u002Fh3>\u003Cp>Created new administrator account 1 with RID 1000 (0x03e8), as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017508666_8_610e4f3946-1.jpeg\">\u003C\u002Fp>\u003Cp>Modified the RID of account a to 1000 (0x03e8)\u003C\u002Fp>\u003Cp>After modification, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017515207_9_4dd5a7c525-1.jpeg\">\u003C\u002Fp>\u003Cp>Logged back into account a\u003C\u002Fp>\u003Cp>Account a inherited the privileges of account 1 and became an administrator\u003C\u002Fp>\u003Cp>The login username changed to 1, while executing whoami \u002Fall shows the username as a, but with RID 1000 (account 1's RID), as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017519939_10_bf0a37fbdb-1.jpeg\">\u003C\u002Fp>\u003Cp>Environment variables correspond to user 1, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017523448_11_8436753d5d-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Intuitive understanding:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Account a transformed into the original account 1, inheriting its privileges, but retains the display of account a in some functions\u003C\u002Fp>\u003Ch2>0x04 Implementation Approach for Script Writing\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>Implementation Approach\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SYSTEM privileges\u003C\u002Fli>\u003Cli>Read registry information of the specified account\u003C\u002Fli>\u003Cli>Modify the fixed offset address, specifying it as the new RID\u003C\u002Fli>\u003Cli>Import the registry to complete the modification\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For specific implementation details, refer to the instructions in the article 'Penetration Techniques – Account Hiding in Windows Systems'\u003C\u002Fp>\u003Cp>Reference code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Since the functionality is relatively simple, the implementation code is left for the reader to complete\u003C\u002Fp>\u003Cp>Corresponding Metasploit module: windows\u002Fmanage\u002Frid_hijack\u003C\u002Fp>\u003Ch2>0x05 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For RID Hijacking, the implementation principle is straightforward:\u003Cstrong>Locate the registry file of the account and modify the location representing the RID information.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>However, the following shortcomings exist in its exploitation:\u003C\u002Fp>\u003Cul>\u003Cli>The account must be logged in again to take effect.\u003C\u002Fli>\u003Cli>Environment variables are modified, affecting normal usage.\u003C\u002Fli>\u003Cli>The display of the username has issues and is easily detectable.\u003C\u002Fli>\u003Cli>Simulating ADMINISTRATOR privileges will create a new user folder.\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Exploitation Scenarios\u003C\u002Fh3>\u003Col>\u003Cli>Enable the guest account, modify the RID, log in to the guest account to obtain high privileges.\u003C\u002Fli>\u003Cli>Modify the RID of a low-privilege user and log in to gain high privileges.\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x06 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From a defensive perspective, the attacker first needs to obtain system privileges on the current system.\u003C\u002Fp>\u003Cp>Detection Approach:\u003C\u002Fp>\u003Cul>\u003Cli>Check if there are any anomalies in the information under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\.\u003C\u002Fli>\u003Cli>Check if the guest account has been enabled.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the implementation method of RID Hijacking, analyzes the exploitation conditions, and provides defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",681,"Onedaysec",4,"published","2026-02-02T07:38:21.177Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"RID Hijacking: Windows Account Privilege Escalation Technique","RID hijacking, Windows security, account privilege escalation, penetration testing, SID, registry hacking",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],898,897,895,{"title":39,"description":39,"image":39},"2026-07-24T15:37:10.950Z","2026-07-23T16:02:14.920Z","draft","2026-07-23T16:15:23.486Z"]