So if i create a file- I am owner , if then SYSTEM moves it into system32- I am still the owner, no files have been created, so no ACL changes.
-
Show this thread
-
There is a special condition here- that is, when this happens, we are not logged in yet... This makes some techniques impossible... So actually for real this calls for some serious creativity. lets ignore nat for now though.....
1 reply 0 retweets 4 likesShow this thread -
What we wanna do is to redirect the files desination so in will get moved to a location we could not do our self. That location should then be trusted in a way that allows us to get the file executed under a higher privileged account.
1 reply 0 retweets 6 likesShow this thread -
I still think my go to method for that works... when windows error reporting service runs as system it tries to load a not existing phoneinfo.dll from system 32. If not then every fucking gui process still desperately try to load the not existing edgegdi.dll .....
1 reply 0 retweets 10 likesShow this thread -
The rename operation do not change the files destination though... How can we redirect the file move to another folder when we cannot transform the folder the existing file is in as it is not empty?
1 reply 0 retweets 4 likesShow this thread -
Well... we dont have to! if we intially make the folder point to c:\temp\ the service will try to move c:\temp\file.exe to c:\recovery\file_s.exe
1 reply 0 retweets 4 likesShow this thread -
if we then make an oplock on the file it open first- we can time it so that when we get the oplock callback, we know its now to change the junction folder so it now points to system32.
1 reply 0 retweets 4 likesShow this thread -
We could also point the folder at "\RPC Control\" and in there make one symlink for source and one for destion. like this:pic.twitter.com/vqccARCQHA
1 reply 0 retweets 6 likesShow this thread -
But this is all a crazy fantasy because in realitity it is impossible to create those symlinks or those oplocks- cuz they dont survive a reboot and we are not logged in yet.....
1 reply 0 retweets 3 likesShow this thread -
This Tweet is unavailable.
We could also create the ntfs symbolic links on the recovery partition... Still needs admin though
-
-
Replying to @jonasLyk
Not if an admin disabled this requirement in Settings - Developer options
0 replies 0 retweets 1 likeThanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.