当前位置:网站首页>[try to hack] at, SC, PS command authorization
[try to hack] at, SC, PS command authorization
2022-07-28 12:16:00 【Hua Weiyun】
Blog home page : Happy star The blog home page of
Series column :Try to Hack
Welcome to focus on the likes collection ️ Leaving a message.
Starting time :2022 year 7 month 10 Japan
The author's level is very limited , If an error is found , Please let me know , thank !
@toc
AT Raise the right
Applicable system :Windows2000、Windows 2003、Windows XP
Premise : Get server admin jurisdiction , have access to at command , Therefore, the right is system jurisdiction
at Is a command-line tool for issuing scheduled tasks , The grammar is relatively simple . adopt at Command issued
Scheduled tasks , Windows Default to SYSTEM Permission to run . Scheduled task scheduling can be batch processing 、 It can be a binary file
at 13:38 /interactive cmd.exe # stay 13:38 With system Permission open cmd
Now we just got one system Of shell, We should raise the power of the system to system Only with authority
In getting a system Of cmd after , Use taskmgr The command calls the task manager , At this time
Task manager is system jurisdiction , then kill fall explore process , Then use the task manager
newly build explore process , Will get a system Desktop environment for
SC Raise the right
Applicable system :Windows7、Windows8、Windows2008、Windows2012、Windows2016
# Create a name syscmd The new interactive cmd service C:>sc Create syscmd binPath= “cmd /K start” type= own type= interact # Start the service to get system The powers of the cmdC:>sc start syscmd among syscmd It's the service name , You can fill in at will ,binpath Is the command to start ,type=own Service refers to who the service belongs to ,type=interact Refers to interactive shell
PS Raise the right
PStool Download address
Applicable system :Windows2003 、 Windows2008psexec.exe -accepteula -s -i -d cmd.exe
边栏推荐
- Alexnet - paper analysis and reproduction
- laravel表单数据验证
- PHP ⽉ the simplest way to add and subtract ⽅
- Simple selection sort and heap sort
- 社区点赞业务缓存设计优化探索
- After abolishing Tencent cloud: meiyabaike won the bid of 98.3 million
- Lua对table进行深拷贝
- SQL注入 Less18(头部注入+报错注入)
- php保留两位小数的几种方法介绍
- Interfaces and abstract classes
猜你喜欢

分布式定时器

REST风格

本地化、低时延、绿色低碳:阿里云正式启用福州数据中心

laravel表单数据验证

Yolov3 complete explanation - from the perspective of data coding

瑞吉外卖——Day01

Unity one key replacement of objects in the scene

Full analysis of seven classical regression analysis methods

Gecko competition 2.0 is new! Come and show your flexible operation skills!

Lua makes a deep copy of table
随机推荐
【Try to Hack】AT、SC、PS命令提权
WebView详解
Skiasharp's WPF self drawn drag ball (case version)
Distributed system (III) construction of distributed transaction service
Anonymous subclass objects of abstract classes
Detailed explanation of boost official website search engine project
Saltstack command injection vulnerability analysis (cve-2020-16846)
Interfaces and abstract classes
Hcip (PAP authentication and chap authentication of PPP)
一些知识概念
Use Baidu PaddlePaddle easydl to complete garbage classification
2022.07.08 summer training personal qualifying (III)
Alexnet - paper analysis and reproduction
Learn to use MySQL explain to execute the plan, and SQL performance tuning is no longer difficult
Service workers let the website dynamically load webp pictures
Redis安装
laravel表单数据验证
Docker runs MySQL service
Start from scratch blazor server (2) -- consolidate databases
Interpretable ml of Li Hongyi's machine learning model