Re: remote privilege escalation

From: Dave Aitel (dave@immunitysec.com)
Date: 01/09/03

  • Next message: Alfred Huger: "Subject: Re: AW: MS Terminal Services open to the world Thread"
    Date: Wed, 8 Jan 2003 22:09:58 -0500
    From: Dave Aitel <dave@immunitysec.com>
    To: javier@liendo.net
    
    

    Also fun is using MSADC, since its enabled by default for localhost...
    -dave

    On Wed, 8 Jan 2003 15:11:16 -0800 (PST)
    Javier Liendo <javier@liendo.net> wrote:

    > hello
    >
    > have you tried
    >
    > http://www.digitaloffense.net/archives/iissystem/
    >
    > regards
    >
    > javir
    >
    > --- Jeremy Bartels <Jeremy.Bartels@allsecure-it.com>
    > wrote:
    > > Hi All,
    > >
    > > Can someone please tell me how I go about escalating
    > > my privileges to SYSTEM
    > > remotely on a windows 2000 Server SP1 'out of the
    > > box' installation.
    > >
    > > I can do it when I am sitting in front of the PC
    > > with ERunAs2X.exe
    > > if I try to use ErunAs2X remotely with: ERunAs2X.exe
    > > "nc.exe -l -p
    > > 50000 -d -e cmd.exe"
    > > I get the error:
    > >
    > > The application failed to initialize properly
    > > (0xc0000142). Click on OK to
    > > terminate the application.
    > >
    > > the title bar of the windows says: cmd.exe -
    > > Application error
    > >
    > > does anyone have any ideas?
    > >
    > > Cheers
    > >
    > > Jeremy
    > >
    > >
    > >
    > >
    > ---------------------------------------------------------------------
    > -------
    > > This list is provided by the SecurityFocus Security
    > > Intelligence Alert (SIA)
    > > Service. For more information on SecurityFocus' SIA
    > > service which
    > > automatically alerts you to the latest security
    > > vulnerabilities please see:
    > > https://alerts.securityfocus.com/
    > >
    >
    >
    > ---------------------------------------------------------------------
    > ------- This list is provided by the SecurityFocus Security
    > Intelligence Alert (SIA) Service. For more information on
    > SecurityFocus' SIA service which automatically alerts you to the
    > latest security vulnerabilities please see:
    > https://alerts.securityfocus.com/
    >
    >

    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
    Service. For more information on SecurityFocus' SIA service which
    automatically alerts you to the latest security vulnerabilities please see:
    https://alerts.securityfocus.com/



    Relevant Pages

    • Re: Arp spoofing & dsniff
      ... If I am on a Switched network and I change my MAC ... For more information on SecurityFocus' SIA ... This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • Re: SQL INJECTION IN Coldfusion
      ... UNION file.cfm?id=4567 UNION SELECT TOP 3 FROM mrro-- ... >> Intelligence Alert ... For more information on SecurityFocus' SIA ...
      (Pen-Test)
    • Re: Citrix pentesting ideas
      ... >testing on Linux and Solaris these dont work as I ... For more information on SecurityFocus' SIA ... This list is provided by the SecurityFocus Security Intelligence Alert ...
      (Pen-Test)
    • Re: Remote shell on Win9X - Summary
      ... >> Donate cash, emergency relief information ... >>- This list is provided by the SecurityFocus ... > Security Intelligence Alert ... >> (SIA) Service. ...
      (Pen-Test)
    • RE: Re-opening an old thread: NetWare-Enterprise-Web-Server/5.1 --As sistence requested.
      ... > This list is provided by the SecurityFocus Security ... > SecurityFocus' SIA service which automatically alerts you to ... This list is provided by the SecurityFocus Security Intelligence Alert ... automatically alerts you to the latest security vulnerabilities please see: ...
      (Pen-Test)