EH-Net
May 24, 2013, 07:51:51 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Escalating Windows --help  (Read 2403 times)
0 Members and 1 Guest are viewing this topic.
impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« on: August 30, 2012, 10:17:25 PM »

Guys

For the last week I got shell in three machines and stuck escalating windows, I tried to use MS11-080 AND PwDump7.exe to get the hashes, etc, etc....

I can upload files to the server and connect with netcat but the user is very limited.

Do you have any site where I can check how to escalate privilege in Windows, I am not asking how to do it (otherwise I will not learn how to do it), I am asking websiteS with some ideas, I've been looking for and trying HARDER, LOL

Thanks.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
shadowzero
Full Member
***
Offline Offline

Posts: 120


It's a UNIX system, I know this!


View Profile
« Reply #1 on: August 30, 2012, 11:10:51 PM »

Try these links:

http://travisaltman.com/windows-privilege-escalation-via-weak-service-permissions/

http://obscuresecurity.blogspot.ca/2011/11/old-privilege-escalation-techniques.html

http://www.room362.com/blog/2012/8/25/post-exploitation-command-lists-request-to-edit.html
Logged
Jamie.R
Sr. Member
****
Offline Offline

Posts: 429


View Profile
« Reply #2 on: August 31, 2012, 03:11:17 AM »

may also want try this tool

http://pentestmonkey.net/tools/windows-privesc-check
Logged

OSWP | Hackingdojo Nidan | eCPPT
impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #3 on: August 31, 2012, 04:24:02 PM »

Thanks guys, I just read two articles of the links and I got a bunch of ideas, good, this is what I was looking for.
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #4 on: August 31, 2012, 07:54:30 PM »

There are several ways. This is a nice new shiny local priv exploit for Windows Server x64:
http://www.exploit-db.com/exploits/20861/

There are other ways too. I just released a local priv exploit for a third party software:
http://www.exploit-db.com/exploits/20915

Point is, look for installed third party apps that have local priv exploits if the box is totally patched.
Logged

impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #5 on: August 31, 2012, 08:01:11 PM »



Point is, look for installed third party apps that have local priv exploits if the box is totally patched.

I agree, this is the part I am working right now, look for weak services and their applications installed.

I know I could find a remote exploit or use meterpreter, but not, I want to do it manually, I got shell with netcat using a asp shell. I need to master it, I think is more difficult to escalate that to get shell.

Also something that mess up a lot is that sometimes when I type the wrong command or wrong way I loose connection, lol..... TRY HARDER and write down how you got shell ASAP
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
cd1zz
Hero Member
*****
Offline Offline

Posts: 561


View Profile WWW
« Reply #6 on: August 31, 2012, 08:09:49 PM »

Oh sorry, now I know what you're doing. If you can transfer files to the server with your aspshell, you can upload your own exe and execute the file. Usually the problem you'll run into there is the non-interactive shell but you can get around that...
Logged

impelse
Hero Member
*****
Offline Offline

Posts: 565


View Profile WWW
« Reply #7 on: August 31, 2012, 09:31:31 PM »

I got some kind of interactive shell but sometimes with some errors stop, anyway I come in
 10 second later, lol
Logged

CCNA, Security+, 70-290, 70-291
CCNA Security
Taking Hackingdojo training

Website: http://blog.thehost1.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines Valid XHTML 1.0! Valid CSS!
Page created in 0.096 seconds with 20 queries.