Windows
powerup
winpeas / windows-exploit-suggester.py
Windows
AlwaysInstallElevated install .msi shell
fodhelper.exe privesc
fodhelper.exe privescAdministrators group account whoami /groups Medium -> High Mandatory level
Weak service permission
A low privileged user is allowed to change service configuration - for example change the service binary the service launches when it starts
A low privileged user can overwrite the binary the service launches when it starts
Unquoted service path
To list nonstandard services that start automatically
find returned service having path without " " and find if precedential dir writable
JuicyPotato ( SeImpersonate / SeAssignPrimaryToken )
SeImpersonate / SeAssignPrimaryToken ) RouguePotato/PrintSpoofer SeImpersonate
SeImpersonatems16-032 (w/o KB3139914)
Create user for persistency as admin/system
RDP login page "ease of access" system cmd
WindowsXP SP0/1 upnphost SSDPSRV
Need: file transfer to victim, low rev shell
PSexec
Last updated