|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Weird privileges? |
|
Posted: Sun Nov 16, 2008 4:25 am |
|
|
ThinSmoke |
Advanced user |
|
|
Joined: Nov 15, 2008 |
Posts: 55 |
|
|
|
|
|
|
|
Hey,
well ive gotten into some box , yet i cant really execute anything usefull for me.
I exploited the forum, waraxe cracked the hash for me, and i uploaded my shell there
Though i cant add user (using net.exe ) nor can i start/stop any service, cant really execute anything at all.
Any idea why?
Rights on every file are drwxrwxrwx , tho i cant delete them somehow, i can write to them tho.
Really weird |
|
|
|
|
Posted: Sun Nov 16, 2008 8:08 am |
|
|
pexli |
Valuable expert |
|
|
Joined: May 24, 2007 |
Posts: 665 |
Location: Bulgaria |
|
|
|
|
|
|
Quote: | Though i cant add user (using net.exe ) nor can i start/stop any service, cant really execute anything at all. |
WOW |
|
|
|
|
|
Re: Weird privileges? |
|
Posted: Sun Nov 16, 2008 9:43 am |
|
|
x3roconf_ |
Advanced user |
|
|
Joined: May 01, 2008 |
Posts: 101 |
|
|
|
|
|
|
|
ThinSmoke wrote: | Hey,
well ive gotten into some box , yet i cant really execute anything usefull for me.
I exploited the forum, waraxe cracked the hash for me, and i uploaded my shell there
Though i cant add user (using net.exe ) nor can i start/stop any service, cant really execute anything at all.
Any idea why?
Rights on every file are drwxrwxrwx , tho i cant delete them somehow, i can write to them tho.
Really weird |
Is it windows or *nix box? |
|
|
|
|
|
Re: Weird privileges? |
|
Posted: Sun Nov 16, 2008 12:51 pm |
|
|
ThinSmoke |
Advanced user |
|
|
Joined: Nov 15, 2008 |
Posts: 55 |
|
|
|
|
|
|
|
x3roconf_ wrote: | ThinSmoke wrote: | Hey,
well ive gotten into some box , yet i cant really execute anything usefull for me.
I exploited the forum, waraxe cracked the hash for me, and i uploaded my shell there
Though i cant add user (using net.exe ) nor can i start/stop any service, cant really execute anything at all.
Any idea why?
Rights on every file are drwxrwxrwx , tho i cant delete them somehow, i can write to them tho.
Really weird |
Is it windows or *nix box? |
Windowss obviously.... |
|
|
|
|
Posted: Sun Nov 16, 2008 1:13 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
What version of windows? Win2k? Win2k3? Other?
It's obvious, that you need to find out your current username/sid and your privileges. And from what platform you got shell - apache/php? IIS/php? |
|
|
|
|
Posted: Sun Nov 16, 2008 11:46 pm |
|
|
_mranderson_ |
Valuable expert |
|
|
Joined: Oct 30, 2008 |
Posts: 51 |
|
|
|
|
|
|
|
I have the same problem, se server is win2k3 and the platform is iis/php, do I need an asp shell? |
|
|
|
|
Posted: Mon Nov 17, 2008 12:24 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
How about php shell functions: exec(), system(), passthru(), popen(), proc_open(), pcntl_exec()? Are they working at some degree? Try "dir" as test command. Look for php info: "safe_mode", "disable_functions"?
And as you can manipulate some files and directories in server, then there are other possibilities - ASP, CGI, Perl, Python - depends on specific server environment.
And of course even after getting into windows command prompt you still have minimal privileges. So adding users, writing critical files, etc - it's just a dream, unless you find a way for local privilege escalation |
|
|
|
|
Posted: Mon Nov 17, 2008 1:14 am |
|
|
ThinSmoke |
Advanced user |
|
|
Joined: Nov 15, 2008 |
Posts: 55 |
|
|
|
|
|
|
|
Well, i went the easy way as i wasnt in a rush or so.
Uploaded a bat and put it in "startup" folder |
|
|
|
|
Posted: Mon Nov 17, 2008 1:36 am |
|
|
_mranderson_ |
Valuable expert |
|
|
Joined: Oct 30, 2008 |
Posts: 51 |
|
|
|
|
|
|
|
all functions are enabled and secure mode is off, still, when you execute even a simple dir command you get 126 as output... I thinks it has something to do with output redirection idk, studying on it.
Escalating priviledges to SYSTEM on a windows machine is easy as stealing cookies to children... there's a local priv escalation exploit on nt boxes within the kernel that microsoft won't fix for win32 under vista (2k,xp,2k3..). And there's another one on vista that microsoft won't fix coz it's a matter of rewriting part of the kernel. |
|
|
|
|
Posted: Mon Nov 17, 2008 2:29 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
Are those privilege escalations publicly available information? Can you provide more info? |
|
|
|
|
Posted: Mon Nov 17, 2008 3:30 am |
|
|
_mranderson_ |
Valuable expert |
|
|
Joined: Oct 30, 2008 |
Posts: 51 |
|
|
|
|
|
|
|
yes I think they are public, and I ve just heard of them anyways, saw a guy using them once, but he was using a script and idk what it did, he didn't tell me. I m sure they are still working |
|
|
|
|
www.waraxe.us Forum Index -> Invision Power Board
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|