Break through abnormal limits again

Source: Internet
Author: User
Tags net command

This scam mainly describes how to break through the elevation of privilege. As for how to upload a SHELL, I wrote it before my blog.

If there is a website that breaks through the first-class information interception system, it is not easy to upload a Trojan, so it is easy to upload it. It cannot execute commands, so it is depressing ..
When the command is initiated, the net user in the command is intercepted,
I want to change my mind.
Running a batch command has the same effect as running a direct command. Since it does not allow the execution of the net command, can I run a batch command?
Click "Create File" in ASP, and rename it "hacker. bat" in the content:
Net usernet user hacker $/del
Net usernet user hacker $ hacker/add
Net localgroup administrators hacker $/add
OK. Save!
Dizzy! Unsuccessful! Directly blocked ....
After being depressed for a while, I tried another method: Get a local batch of commands and upload them. The interception system will not block the files, will it?
OK. Upload!
Dizzy! Again blocked !...
Does this guy really see the file content?
So what does it look like?
To the server by OD?
Not realistic... the real EXE program will not keep the commands in the program as they are,
Try writing a program by yourself?
Dizzy! No tools... no experience...
Forget it
Go home and read the e-books... many articles of the Green League from ..
I saw an article about 2000 system Input Method Vulnerability intrusion. At the end of the article, the author raised several questions. Later, some experts answered the question.
Seeing the answer to these questions, I suddenly found a way to break through the first-class information interception system to execute commands ..
.
1. Prepare the permission escalation command: cmd.exe/c net user hacker/add & net localgroup administrators hacker/add
2. Create a shortcut and write the elevation command in the address bar.
3. Upload this shortcut
4. Run this shortcut with the help of the permission escalation tool .....
5. The Administrator is successfully added ....

 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.