当前位置:网站首页>【Try to Hack】AT、SC、PS命令提权
【Try to Hack】AT、SC、PS命令提权
2022-07-28 11:24:00 【华为云】
博客主页:开心星人的博客主页
系列专栏:Try to Hack
欢迎关注点赞收藏️留言
首发时间:2022年7月10日
作者水平很有限,如果发现错误,还望告知,感谢!
@toc
AT提权
适用系统:Windows2000、Windows 2003、Windows XP
前提:获得服务器admin权限,可以使用at命令,由此提权为system权限
at 是一个发布定时任务计划的命令行工具,语法比较简单。通过 at 命令发布的
定时任务计划, Windows 默认以 SYSTEM 权限运行。定时任务计划可以是批处理、可以是一个二进制文件
at 13:38 /interactive cmd.exe #在13:38以system权限打开cmd
现在我们只是获得了一个system的shell,要把系统提权到system权限才行
在得到一个system的cmd之后,使用taskmgr命令调用任务管理器,此时的
任务管理器是system权限,然后kill掉explore进程,再使用任务管理器
新建explore进程,将会得到一个system的桌面环境
SC提权
适用系统:Windows7、Windows8、Windows2008、Windows2012、Windows2016
# 创建一个名叫syscmd的新的交互式的cmd服务C:>sc Create syscmd binPath= “cmd /K start” type= own type= interact #启动服务获取system权限的cmdC:>sc start syscmd 其中syscmd是服务名称,可以随意填写,binpath是启动的命令,type=own是指服务这个服务属于谁,type=interact是指交互式shell
PS提权
PStool下载地址
适用系统:Windows2003 、 Windows2008psexec.exe -accepteula -s -i -d cmd.exe
边栏推荐
- Design process sharing of wireless anti loss alarm based on single chip microcomputer
- Develop your own NPM package from 0
- 玩转诗词-领略古诗文之美
- Client service registration of Nacos registry
- REST风格
- Learn to use MySQL explain to execute the plan, and SQL performance tuning is no longer difficult
- Business visualization - make your flowchart'run'(4. Actual business scenario test)
- CentOS 7 install MySQL 5.7 & uninstall MySQL 5.7
- QT writing IOT management platform 42 data query export print
- Some knowledge concepts
猜你喜欢

Service workers let the website dynamically load webp pictures

从0开发一个自己的npm包

Unity one key replacement of objects in the scene
![[leetcode] 7. valid anagram · effective letter ectopic words](/img/bc/9806df1358c6f09db03ef2e771aa5a.png)
[leetcode] 7. valid anagram · effective letter ectopic words

Hcip (condition matching and OSPF packet related knowledge)

The game process and the underlying implementation are gradually completed

Detailed explanation of boost official website search engine project

QT writing IOT management platform 42 data query export print

Lua 中 __index、__newindex、rawget、rawset的理解

15. User web layer services (III)
随机推荐
业务可视化-让你的流程图'Run'起来(4.实际业务场景测试)
Go deadlock - when the channel meets mutex
15. User web layer services (III)
STL の 概念及其应用
Opencv notes sorting [Hough transform]
STL concept and its application
ObjectAnimator使用注意点
Force buckle 7_ 1672. Total assets of the richest customers
Upgrading of computing power under the coordination of software and hardware, redefining productivity
Loongarch Godson architecture document collection
Lyscript get previous and next instructions
Alexnet - paper analysis and reproduction
Play with poetry - appreciate the beauty of ancient poetry
Reasons and solutions for moving the first column to the last column in El table
Image filter from the perspective of convolution
Several ways to bind controls --butterknife/viewbinding/databinding
Use Baidu PaddlePaddle easydl to complete garbage classification
什么是WordPress
[pyGame practice] when the end of the world comes, how long can you live in a cruel survival game that really starts from scratch?
Lua makes a deep copy of table