Tools

PrintSpoofer

User enum

whoami /all

if SeAssignPrimaryToken or SeImpersonate you're good to go (Y)

Execute the following command:

Juicy Potato

User enum

whoami /all

if SeAssignPrimaryToken or SeImpersonate you're good to go (Y)

Check for the OS system, and then use the CLSID from:

Execute the following command (using you CLSID):

SMBGhost

Starting with line 204 in exploit.cpp, replace the shellcode with a reverse shell:

Using Visual Studio set the target to x64 and Release and compile the exploit.

Last updated