joakim, on 08 April 2012 - 12:45 PM, said:
It is based on token duplication and not remote threads as I described.
Devxexec works very well.
GL
This post has been edited by GrofLuigi: 24 July 2012 - 08:42 AM
Posted 24 July 2012 - 08:40 AM
joakim, on 08 April 2012 - 12:45 PM, said:
This post has been edited by GrofLuigi: 24 July 2012 - 08:42 AM
Posted 03 August 2012 - 03:36 AM
HKEY_LOCAL_MACHINE\SECURITY\Policy\Accounts\S-1-5-21-645709764-2570854657-2333822770-500\Privilgs
This post has been edited by GrofLuigi: 03 August 2012 - 03:41 AM
Posted 27 September 2012 - 09:20 PM
Posted 27 September 2012 - 11:28 PM
dencorso, on 27 September 2012 - 09:20 PM, said:
Posted 29 September 2012 - 08:00 AM
Quote
net start trustedinstaller C:\windows\system32\runassystem_x64 "C:\windows\system32\runfromtoken_x64 trustedinstaller.exe 1 cmd"
net start UI0Detect net start trustedinstaller C:\windows\system32\runassystem_x64 "C:\windows\system32\runfromtoken_x64 trustedinstaller.exe 1 cmd"?
Posted 30 September 2012 - 09:19 AM
runassystem_x64 regedit
Running in session: 1 Host PID: 872 CreateProcessAsUserW / CreateProcessWithTokenW: A required privilege is not held by the client.
Posted 30 September 2012 - 09:28 AM
tommyp, on 30 September 2012 - 09:19 AM, said:
Posted 01 October 2012 - 07:35 AM
Posted 01 October 2012 - 12:38 PM
Posted 01 October 2012 - 02:35 PM
Posted 02 October 2012 - 06:37 AM
Posted 03 October 2012 - 01:39 AM
Posted 03 October 2012 - 02:38 AM
Posted 04 October 2012 - 03:10 PM
Posted 04 October 2012 - 04:04 PM
tommyp, on 04 October 2012 - 03:10 PM, said:
Posted 05 October 2012 - 03:51 AM
The Windows Modules Installer service is starting. The Windows Modules Installer service was started successfully.
Now setting privilege: SeDebugPrivilege Now setting privilege: SeAssignPrimaryTokenPrivilege Now setting privilege: SeIncreaseQuotaPrivilege Running in session: 1 Host PID: 624 New process created successfully: 2336
nt authority\system
Posted 05 October 2012 - 09:12 AM
tommyp, on 05 October 2012 - 03:51 AM, said:
nt authority\system
C:\windows\system32\runassystem_x64 "C:\windows\system32\runfromtoken_x64 trustedinstaller.exe 1 cmd"
Posted 05 October 2012 - 03:51 PM
Posted 05 October 2012 - 05:30 PM
Posted 06 October 2012 - 06:41 AM