Method 1:
In the iisenvironment, if the permissions are not strict, we have the right to directly access the wmiprvse.exe process in aspxmari. Process view directly drops K
It will run again after the end, and the PID value at this time is different. At this time, we will return to run exp. Direct second kill.
Method 2:
Generally, the virtual host has strict permissions and does not end with permissions. In this case, we can use other overflow tools to forcibly restart the server.
For example, the 3389 blue screen exp that was released some time ago (a lot of tests can be done with patches)
It can even be a brute-force attack. If the server is disconnected after a second of DDOS, the server will be killed immediately after it is restarted (even when IIS is restarted.
Method 3:
From the perspective of the expsource code, let the worker query wmiprvse.exe multiple times (or find it in a special way) in the running process. Here I will not leave it out, just let everyone know the method, just compile it by yourself.
I saw a help post sent by a friend in the forum just now, so I took the liberty to write it. It is not a technical article. Cool float, don't step on it ~~~~~ It's just a bit of experience.
------------------------------------------------------------------------------
Reply:
(Note: A lot of malicious responses irrelevant to content can be ignored ......)
2 # webshell published at five days ago
There is another way to think that the oil is violent.
5 # keio posted at five days ago
I usually switch to multiple iis6 aspx to directly end that process, which may cause the website to crash!
6 # ahuyangok posted at five days ago
Reply 5 # keio
This will not cause the website to fail. You can rest assured. It is similar to a process to clear the site cache. There will be no impact. Rest assured.
Www.2cto.com
8 # ahuyangok posted at five days ago
Reply 4 # huqingkui
When multiple software is used, a large number of packages are sent. If the configuration is poor, it seems that flash sales can still be used.
9 # ahuyangok posted at five days ago
Reply 2 # webshell
If I did not guess the error, the violent run you know means to directly run a wmiprvse.exe, right?
In my tests, it cannot be implemented. He will always prompt time 1.2.3.4 and will not convert it to system
I guess it may be because I run it like this and it only inherits the everyone permission. The system inherits system, which leads to an endless loop.
I do not know whether it is accurate. It is to be confirmed.
10 # webshell published at five days ago
Reply 9 # ahuyangok
Let's just say that the last time the oil was mentioned, there was a problem with privilege escalation. I will say that I have connected to several shells and kept running exp. Run all kinds of exp. Then it succeeded. The oil said this was a brute force operation.
11 # posting at PM five days ago
In fact, a few more executions can be successful! If you start with the source code! You can k wmiprvse.exe! Wmiprvse.exe will run automatically later! Then, the success rate of Elevation of Privilege is very high ..
From blog of smelly sock