Re: priviledge escalation techniques

From: Pieter Danhieux (pdanhieux_at_easynet.be)
Date: 01/22/05

  • Next message: Thor: "Re: priviledge escalation techniques"
    Date: Sat, 22 Jan 2005 20:36:13 +0100
    To: "Eyal Udassin" <eyal@swiftcoders.com>
    
    

    On 22 Jan 2005, at 09:20, Eyal Udassin wrote:

    > Hi,
    >
    > The easiest way to perform privilege escalation on windows, whatever
    > version, is to list the executables in the
    > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    > registry
    > key. All of these executables are run under SYSTEM.
    >
    > Once you get hold of that list, see if you have write permissions to
    > replace
    > the original executable with your own. Don't forget to execute the
    > original
    > from your code, or otherwise you may cause the system to become
    > unstable.
    >
    > I had a client which had such a key pointing to an old printer
    > installation
    > utility which no longer existed, in an unprotected directory outside of
    > "program files". That was the beginning of the end of the pentest :-)
    >
    > If all the files can't be overridden, try to boot with command line
    > only and
    > replace them. Another approach is to remove the hard drive and perform
    > the
    > switch on another computer, with the victim HD as a secondary drive.
    >
    > Eyal Udassin - Swift Coders
    > POB 1596 Ramat Hasharon, 47114
    > 972+547-684989
    > eyal@swiftcoders.com - www.swiftcoders.com

    Or you can use a linux live cd that supports NTFS read/write
    operations. If have already tested KANOTIX and the captive-ntfs
    filesystem (which used the windows drivers to read/write on ntfs)

    regards

    --
    Pieter Danhieux, CISSP, GSEC
    

  • Next message: Thor: "Re: priviledge escalation techniques"

    Relevant Pages

    • Re: svcnxp32.exe, Part 2
      ... > There are a few more posts on this, Frank. ... >> registry, both of which were promptly deleted. ... Windows Update site, the version of wuauclt.exe that seemed to be ... svcnxp32.exe and svcnv32.exe reappeared, but not the executables. ...
      (microsoft.public.windowsupdate)
    • RE: priviledge escalation techniques
      ... All of these executables are run under SYSTEM. ... Subject: priviledge escalation techniques ... I have tried the sethc.exe one, the 'at' command scheduler technique and the ... The OS I used was windows XP pro sp2. ...
      (Pen-Test)
    • Re: priviledge escalation techniques
      ... SYSTEM credentials for executables in the Run key would ... Subject: priviledge escalation techniques ... The easiest way to perform privilege escalation on windows, ... read & execute and list (this folder, subfolders and files), create ...
      (Pen-Test)
    • RE: priviledge escalation techniques
      ... executables listed definitely run under system privileges or with the ... [Insert your favourite comment about editing the registry here, ... Subject: priviledge escalation techniques ... The easiest way to perform privilege escalation on windows, ...
      (Pen-Test)
    • Re: Ubunto 8.10 and AVG 7.5.51
      ... If you're running a mail server, ClamAV would be best bet, although I ... Windows viruses to Windows users. ... file sharing and/or forwarding executables to people. ... I am going to be setting up a Linux server in my apartment for use as ...
      (Ubuntu)