wait- what stops you from just opening the windowstation in another session - the doing relative open to that?
-
-
Replying to @jonasLyk
Results in access denied from RtlGetLastNtStatus. This is with granting Everyone : Full Control on the entire WinSta in WinObjEx as well as on the desktop, and running as system. Lol. Strange that NtUserOpenWindowStation is fine but NtUserOpenDesktop not
1 reply 0 retweets 0 likes -
Replying to @winlogon0
tried making sure you have access to every objdir in the path to reach it?
1 reply 0 retweets 0 likes -
Replying to @jonasLyk @winlogon0
or wait- is it in session 0 you try to open`?
2 replies 0 retweets 0 likes -
-
Replying to @winlogon0
HANDLE hToken = {}; OpenProcessToken( GetCurrentProcess(), TOKEN_ALL_ACCESS, &hToken ); DuplicateTokenEx( hToken, TOKEN_ALL_ACCESS, nullptr, SecurityAnonymous, TokenPrimary, &hToken ); SetTokenInformation(hToken, TokenSessionId, &sessionId, sizeof(sessionId));
3 replies 0 retweets 0 likes -
Replying to @jonasLyk
OK so tried just that + ImpersonateLoggedOnUser(hToken); and verified with Process Hacker that that thread is running as Session 2 from a Thread Token it now has. Surprisingly this too fails with the NT Status of AccessDenied = 0xc0000022. Was a good try tho. Idk why it fails!
1 reply 0 retweets 0 likes -
-
Replying to @jonasLyk
Not familiar with that or this tool. Can ya link me up and I’ll try this later?
2 replies 0 retweets 0 likes -
Replying to @winlogon0
https://github.com/googleprojectzero/sandbox-attacksurface-analysis-tools/tree/master/TokenViewer … by mr. forshaw
2 replies 1 retweet 1 like
I need my: https://github.com/BurntSushi/ripgrep … https://www.voidtools.com/ https://github.com/tyranid/oleviewdotnet … http://www.zezula.net/en/fstools/filetest.html … https://docs.microsoft.com/en-us/sysinternals/downloads/procmon … https://processhacker.sourceforge.io/ https://github.com/hfiref0x/WinObjEx64 … to function
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.