Convert system permissions to User Permissions

Source: Internet
Author: User

A few days ago, I spent a lot of effort to get an administrator machine. I circled the main site for a long time and opened 80 without a breakthrough. There was also a high-end port, of course 3389, the Administrator will log on to the server 3389.

I got it on the machine and flipped through what was in the Administrator's machine. I originally wanted to install the keyboard record and found many rdp files named after ip addresses, next time I came back and looked at it. Fortunately, I saved the password in the rdp file (in this case, I only read the rdp password, but I cannot remember the key record ). The 3389 of the Main Station and the sub-stations are logged on by saving the password. You can read the password by uploading something that reads the rdp password. However, this is a headache, my Trojan is a system permission horse. The password for reading rdp files must be under the user permission. If you want to install a user permission, you can immediately get rid of it. The administrator has installed Kaspersky on the machine and enabled active defense. I tried to get rid of it. I installed other horses and they were all blocked by active defense. The Administrator also seemed to find that he started to check the machine. Fortunately, the horse was still stable and disconnected first.

Next, let's take a closer look. In the end, we have to get a shell with the user permission, and then upload and execute it right away, so we can't even get rid of the current permission.

Finally, I tried to directly use the license card Conversion Tool to run rdpcrk.exe and redirect the parameters to the text. The result was not read successfully. So I thought of using nc to convert a shell with the user permission through the token.

Run cmd: change.exe c: windowsc.exe xx. xx 123-e cmd.exe in the Trojan.

In the local listening port 123, after receiving the shell, upload something, whoami, haha, and finally get a shell with user permissions.
Then rdpcrk.exe xx. rdp
You can get the password and log on to the server.

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.