Tools
PrintSpoofer
User enum
whoami /all
if SeAssignPrimaryToken or SeImpersonate you're good to go (Y)
Execute the following command:
Juicy Potato
User enum
whoami /all
if SeAssignPrimaryToken or SeImpersonate you're good to go (Y)
Check for the OS system, and then use the CLSID from:
Execute the following command (using you CLSID):
SMBGhost
Starting with line 204 in exploit.cpp, replace the shellcode with a reverse shell:
Using Visual Studio set the target to x64 and Release and compile the exploit.
Last updated