
Manipolazione e abuso dei token di accesso di Windows.
Manipolazione e abuso dei token di accesso di Windows.
TokenPlayer è solo un piccolo strumento che ho realizzato per imparare la programmazione dell'API win32 e comprendere meglio il modello dei token di accesso di Windows.
General options:
--help Display help menu.
Impersonation Options:
--impersonate Impersonates the specified pid and spawns a new child
process under its context.
--pid arg Proccess ID to steal the token from.
--spawn Spawns a new command prompt under the context of the
stolen token.
Execution Options:
--exec Execute an instance of a specified program under the
impersonated context.
--pid arg Proccess ID to steal the token from.
--prog The full path to the program to be executed.
--args Optional execution arguments for the specified
program.
Make Token Options:
--maketoken Create a new process under a set of creds for only
network authentication (Similar to runas /netonly).
--username arg Username
--password arg Password in plaintext format.
--domain arg The domain the user belongs, if domain isn't specified
the local machine will be used.
UAC Bypass Options:
--pwnuac Will try to bypass UAC using the token-duplication
method.
--spawn Spawns a new elevated prompt.
--prog arg The full path to the program to be executed.
--args arg Optional execution arguments for the specified
program.
Parent Process Spoofing Options:
--spoofppid Spawn a new instance of an application with spoofed
parent process.
--ppid arg The PID of the parent process.
--prog arg The full path to the program to be executed.
--args arg Optional execution arguments for the specified
program.






Per compilarlo da solo dovrai installare la libreria boost, perché viene usata per il parsing e la gestione degli argomenti della riga di comando. Dovrai inoltre specificare la cartella della libreria esterna nelle impostazioni del progetto.