Penetration Testing mailing list archives

RE: Windows privelege escalation?


From: <Cedric.Baechler () vtg admin ch>
Date: Wed, 13 Jul 2005 13:52:28 +0200

I've had success with a public exploit for MS04-044 that i slightly modified and that give you SYSTEM privileges on any 
Win2k SP4.

Cedric

-----Message d'origine-----
De : Bones [mailto:the.bones () gmail com] 
Envoyé : mercredi, 13. juillet 2005 00:01
À : pen-test () securityfocus com
Objet : Windows privelege escalation?

All,

Working on a pen-test here where low-privilege user accounts are easy enough to obtain on some target servers, however, 
escalating privs is giving us some fits.

Most of the targets are Win2003 or Win2000-SP4. 

What is the current state of escalating privileges on Windows hosts?
Any new tools or working exploits out there which are publicly accessible? Most of the silver bullets of the past (like 
PipeUpSam,
PipeUpAdmin) are of course no longer usable largely after Win2000-SP3.
We did find some exploits (MS05-012, etc.) that might have worked, but this client is patched pretty solid.

Interested to see the feedback...

--
Bones*
the.bones () gmail com


Current thread: