remote privilege escalation

From: Jeremy Bartels (Jeremy.Bartels@allsecure-it.com)
Date: 01/08/03

  • Next message: Joe Luna: "PerlModule Apache::AuthDBI"
    From: "Jeremy Bartels" <Jeremy.Bartels@allsecure-it.com>
    To: <pen-test@securityfocus.com>
    Date: Wed, 8 Jan 2003 15:10:32 +1100
    
    

    Hi All,

    Can someone please tell me how I go about escalating my privileges to SYSTEM
    remotely on a windows 2000 Server SP1 'out of the box' installation.

    I can do it when I am sitting in front of the PC with ERunAs2X.exe
    if I try to use ErunAs2X remotely with: ERunAs2X.exe "nc.exe -l -p
    50000 -d -e cmd.exe"
    I get the error:

    The application failed to initialize properly (0xc0000142). Click on OK to
    terminate the application.

    the title bar of the windows says: cmd.exe - Application error

    does anyone have any ideas?

    Cheers

    Jeremy

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/



    Relevant Pages

    • Re: faster scans? (nmap)
      ... one host using nmap for syn scans in burst mode with the ... >>>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • Re: pen test help please asap
      ... > Machine A on client site makes a configurable encrypted OUTBOUND ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • Re: ettercap help
      ... Anyways have never tried Ettercap for VNC. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ... This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • Re: ettercap help
      ... > I can get it to sniff telnet, ftp, pop, smb, but no vnc. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)
    • Re: Wardialing
      ... >>> achieving the connection with the modem. ... >>This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
      (Pen-Test)