Re: Escalation of privilege

From: Torgeir Bakken (MVP) (Torgeir.Bakken-spam_at_hydro.com)
Date: 11/24/03


Date: Mon, 24 Nov 2003 10:42:10 +0100

Nicolas Macarez wrote:

> Torgeir Bakken (MVP) wrote:
> >
> > At least one of the buy-products can do this it looks like:
> >
> > From http://www.netexec.de/
> >
> > <quote>
> > Temporary Administrator group memberships
> >
> > Another feature that make NetExec a excellent choice for software
> > installation scenarios are extended group memberships. Using this
> > feature it is possible to run a process under a non-privileged user
> > account, but inside this process the user becomes also a member of
> > the Administrators group. Therefore the app uses the profile,
> > settings and home directory of the non-privileged user account,
> >but runs with Administrator privileges.
> > </quote>
>
> Torgeir,
> I ran netexec, mainly the localexec utility w/ the command line features.
> The command line syntax was :
>
> localexec C:\Scripts\leader.vbs ACCOUNT=administrateur
> PASSWORD=PassAdmin2003 /NODIALOG /NOPROFILE
>
> I ran this command as leader4, a user without any admin privileges.
>
> Unfortunately, again it was the registry of the administrateur account which
> was modifed, and not that of leader4.
> It seems that it is not was you say above - unless I am not running the tool
> correctly, with the suitables options, whihch is what I hope...
>
> Help greatly appreciated and thanks for your patience!

Hi

I haven't used this product myself, but I took a look at he help file and didn't
get any wiser of that. You could maybe send a e-mail to the company and ask them
about this: http://www.netexec.de/kontakt.html

--
torgeir
Microsoft MVP Scripting and WMI, Porsgrunn Norway
Administration scripting examples and an ONLINE version of the 1328 page
Scripting Guide: http://www.microsoft.com/technet/scriptcenter


Relevant Pages

  • Re: Games
    ... When I got the list of Users, the account/username I use was not even ... >> attempted to run one of the game programs. ... both are members of the Administrator Group. ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Not an existing data source name. Invalid DSN.
    ... Administrator.NewDomain are in the Administrator group and have the ... current active account like user.NewDomain, ... Microsoft Online Community Support ...
    (microsoft.public.data.odbc)
  • Terminal Services Policies
    ... You can apply policy for user group specific and refuse ... for Administrator Group. ... You must edit properties security GPO and put security ... for not apply GPO to Administrator group ...
    (microsoft.public.windows.server.general)
  • Re: Users cannot run local appliactions .. pls help!!...
    ... Went to computer management, local user, ... groups - and put the domain user in the administrator group, ... > "Don't lose sight of security. ...
    (microsoft.public.win2000.security)
  • Re: 530 user xxxxx cannot log in.
    ... by default if user belong to Administrator group they ... you might want to check the user right for administrator group... ... >>>from a client PC or script, FTP fails ... >>>from client PC or batch script. ...
    (microsoft.public.inetserver.iis)