[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fq2CoQRD6s_XC1RsX5oz3xNX5ZvPdqvzMNG3mfQhYVmg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1137,"How can SeBackupPrivilege be used to extract password hashes from a Windows system?","SeBackupPrivilege grants read access to any file on the system, typically assigned to backup service accounts. An attacker can enable this privilege, then read the registry hives `HKEY_LOCAL_MACHINE\\SAM`, `SECURITY`, and `SYSTEM` to dump all user password hashes. Tools like Mimikatz can then extract hashes with `lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv`. This privilege escalation path is a key focus in [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges).","\u003Cp>SeBackupPrivilege grants read access to any file on the system, typically assigned to backup service accounts. An attacker can enable this privilege, then read the registry hives `HKEY_LOCAL_MACHINE\\SAM`, `SECURITY`, and `SYSTEM` to dump all user password hashes. Tools like Mimikatz can then extract hashes with `lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv`. This privilege escalation path is a key focus in [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-sebackupprivilege-be-used-to-extract-password-hashes-from-a-windows-syst-1777480365449","SeBackupPrivilege, password hash extraction, registry dump, Mimikatz, SAM",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},276,"Penetration Techniques - Exploitation of Nine Windows Privileges","penetration-techniques-exploitation-of-nine-windows-privileges","Learn to exploit nine Windows privileges like SeImpersonatePrivilege for privilege escalation. Techniques include token theft, NTLM relay, and open-source tools for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previous articles \"Penetration Techniques - Switching from Admin to System Privileges\" and \"Penetration Techniques - Token Theft and Exploitation\" introduced methods to switch from admin privileges to system and TrustedInstaller privileges respectively, with the primary approach being token-based privilege switching.\u003C\u002Fp>\u003Cp>So, what exploitable methods exist for special tokens of regular users (or LocalService users)? Can privilege escalation be achieved? How to determine?\u003C\u002Fp>\u003Cp>This article will combine personal experience, reference multiple open-source tools and materials, attempt to summarize this technique, and share learning insights.\u003C\u002Fp>\u003Cp>Referenced open-source tools and materials:\u003C\u002Fp>\u003Cul>\u003Cli>Hot Potato: https:\u002F\u002Fgithub.com\u002Ffoxglovesec\u002FPotato\u003C\u002Fli>\u003Cli>PowerShell version Hot Potato: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FTater\u003C\u002Fli>\u003Cli>Rotten Potato: https:\u002F\u002Fgithub.com\u002Fbreenmachine\u002FRottenPotatoNG\u003C\u002Fli>\u003Cli>lonelypotato: https:\u002F\u002Fgithub.com\u002Fdecoder-it\u002Flonelypotato\u003C\u002Fli>\u003Cli>Juicy Potato: https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u003C\u002Fli>\u003Cli>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F01\u002F16\u002Fhot-potato\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F09\u002F26\u002Frotten-potato-privilege-escalation-from-service-accounts-to-system\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Brief exploitation approach\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTcbPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeBackupPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeRestorePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Brief Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. After gaining access to the target, check available privileges\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fpriv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example, the privileges a regular user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016711270_0_2fce7dd500.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an administrator user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016716189_1_44d2f30554.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an IIS user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721684_2_39f9f7bc1c.jpeg\">\u003C\u002Fp>\u003Cp>The 'Privilege Name' item indicates the privileges held, and 'State' indicates the status of the privilege. We can use the WinAPI AdjustTokenPrivileges to set the privilege to Disabled or Enabled\u003C\u002Fp>\u003Cp>Reference implementation code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling a specified privilege (SeDebugPrivilege) and viewing the current username and held privileges\u003C\u002Fp>\u003Ch3>2. If the following nine privileges are included, we can further exploit them\u003C\u002Fh3>\u003Cul>\u003Cli>SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>SeTcbPrivilege\u003C\u002Fli>\u003Cli>SeBackupPrivilege\u003C\u002Fli>\u003Cli>SeRestorePrivilege\u003C\u002Fli>\u003Cli>SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Users of IIS or SQL Server typically have SeImpersonatePrivilege and SeAssignPrimaryPrivilege permissions.\u003C\u002Fp>\u003Cp>Backup service users typically have SeBackupPrivilege and SeRestorePrivilege permissions.\u003C\u002Fp>\u003Ch2>0x03 Exploitation Ideas for SeImpersonatePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L327\u003C\u002Fp>\u003Ch3>SeImpersonatePrivilege\u003C\u002Fh3>\u003Cp>Impersonate a client after authentication\u003C\u002Fp>\u003Cp>Processes with this privilege can impersonate existing tokens but cannot create new tokens\u003C\u002Fp>\u003Cp>The following users have this privilege:\u003C\u002Fp>\u003Cul>\u003Cli>Local Administrators group members and local service accounts\u003C\u002Fli>\u003Cli>Services started by the Service Control Manager\u003C\u002Fli>\u003Cli>COM servers launched by the Component Object Model (COM) infrastructure and configured to run under a specific account\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically, IIS or SQL Server users have this privilege\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Obtain a System user token via NTLM Relay to Local Negotiation\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Can use open-source tools such as Rotten Potato, LonelyPotato, or Juicy Potato\u003C\u002Fp>\u003Col>\u003Cli>Create a new process using the WinAPI CreateProcessWithToken, passing the System user token\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Requires SeImpersonatePrivilege to succeed\u003C\u002Fp>\u003Col>\u003Cli>This token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeImpersonatePrivilege permission of the current process, calls CreateProcessWithToken, passes the current process's Token to create a process, and can be used with RottenPotato to escalate privileges from LocalService to System\u003C\u002Fp>\u003Ch2>0x04 Exploitation ideas for SeAssignPrimaryPrivilege permission\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L359\u003C\u002Fp>\u003Ch3>SeAssignPrimaryPrivilege\u003C\u002Fh3>\u003Cp>Assign a token to a process (newly created or suspended)\u003C\u002Fp>\u003Cp>Typically, iis or sqlserver users have this permission\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Use NTLM Relay to Local Negotiation to obtain the System user's Token\u003C\u002Fli>\u003Cli>Create a new process via WinAPI CreateProcessAsUser, passing the System user's Token\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeAssignPrimaryTokenPrivilege privilege for the current process, calls CreateProcessAsUser, passes the current process's Token to create a process, and combined with RottenPotato, can be used to escalate privileges from LocalService to System.\u003C\u002Fp>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain the System user's Token by exploiting NTLM Relay to Local Negotiation\u003C\u002Fli>\u003Cli>Create a suspended new process via the WinAPI CreateProcess, with the parameter set to CREATE_SUSPENDED\u003C\u002Fli>\u003Cli>Replace the new process's Token with the System user's Token via the WinAPI NtSetInformationProcess\u003C\u002Fli>\u003Cli>This Token possesses System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>Exploitation approach for the 0x05 SeTcbPrivilege privilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L418\u003C\u002Fp>\u003Ch3>SeTcbPrivilege\u003C\u002Fh3>\u003Cp>Equivalent to obtaining the highest system privileges\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Call LsaLogonUser to obtain a Token\u003C\u002Fli>\u003Cli>Add this Token to the Local System account group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeTcbPrivilege for the current process, logs in user test1, adds it to the Local System account group, obtains System privileges, and creates registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testtcb\u003C\u002Fp>\u003Ch2>0x06 Exploitation approach for SeBackupPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L495\u003C\u002Fp>\u003Ch3>SeBackupPrivilege\u003C\u002Fh3>\u003Cp>Used to perform backup operations, has read permissions for any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Read registry HKEY_LOCAL_MACHINE\\SAM, HKEY_LOCAL_MACHINE\\SECURITY, and HKEY_LOCAL_MACHINE\\SYSTEM\u003C\u002Fli>\u003Cli>Export all user hashes from the current system\u003C\u002Fli>\u003C\u002Fol>\u003Cp>mimikatz command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeBackupPrivilege of the current process, reading the registry, and saving it to files C:\\\\test\\\\SAM, C:\\\\test\\\\SECURITY, and C:\\\\test\\\\SYSTEM\u003C\u002Fp>\u003Ch2>0x07 Exploitation ideas for SeRestorePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L528\u003C\u002Fp>\u003Ch3>SeRestorePrivilege\u003C\u002Fh3>\u003Cp>Used to perform restore operations, granting write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege, modify the registry `HKLM\\SOFTWARE\\Microsoft\\Windows\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options`\u003C\u002Fp>\u003Col>\u003Cli>Hijack the startup of exe files\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation Idea 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege permission, write dll files to arbitrary paths\u003C\u002Fli>\u003Cli>Achieve dll hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeRestorePrivilege for the current process, creating the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testrestore\u003C\u002Fp>\u003Ch2>0x08 Exploitation Idea for SeCreateTokenPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L577\u003C\u002Fp>\u003Ch3>SeCreateTokenPrivilege\u003C\u002Fh3>\u003Cp>Used to create Primary Token\u003C\u002Fp>\u003Ch3>Exploitation idea\u003C\u002Fh3>\u003Col>\u003Cli>Create Primary Token via WinAPI ZwCreateToken\u003C\u002Fli>\u003Cli>Add Token to local administrator group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeCreateTokenPrivilege for the current process, creating a Primary Token, adding it to the local administrator group, and enabling SeDebugPrivilege and SeTcbPrivilege\u003C\u002Fp>\u003Ch2>0x09 SeLoadDriverPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L626\u003C\u002Fp>\u003Ch3>SeLoadDriverPrivilege\u003C\u002Fh3>\u003Cp>Used to load driver files\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Create registry entries for driver files\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv ImagePath \u002Ft REG_SZ \u002Fd \"\\??\\C:\\test\\Capcom.sys\"\u003Cbr>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Load driver file Capcom.sys\u003C\u002Fli>\u003Cli>Capcom.sys contains a vulnerability; after system loading, privileges can be escalated from ordinary user to System level. Reference exploit code:\u003C\u002Fli>\u003C\u002Fol>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftandasat\u002FExploitCapcom\u003C\u002Fp>\u003Col>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeLoadDriverPrivilege for the current process, reads registry key hkcu\\System\\CurrentControlSet\\CAPCOM, and loads driver file Capcom.sys\u003C\u002Fp>\u003Ch2>0x0A Exploitation approach for SeTakeOwnershipPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L688\u003C\u002Fp>\u003Ch3>SeTakeOwnershipPrivilege\u003C\u002Fh3>\u003Cp>Similar to SeRestorePrivilege, grants write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege, modify registry `HKLM\\SOFTWARE\\Microsoft\\Windows`\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options\u003C\u002Fp>\u003Col>\u003Cli>Hijacking EXE file startup\u003C\u002Fli>\u003Cli>Achieving privilege escalation or acting as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege permissions to write DLL files to arbitrary paths\u003C\u002Fli>\u003Cli>Implement DLL hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or act as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code enables SeTakeOwnershipPrivilege for the current process, modifies permissions for the registry key hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options, granting full operational permissions to standard user accounts\u003C\u002Fp>\u003Cp>Subsequent write operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\" \u002Fv takeownership \u002Ft REG_SZ \u002Fd \"C:\\\\Windows\\\\System32\\\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x0B SeDebugPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L736\u003C\u002Fp>\u003Ch3>SeDebugPrivilege\u003C\u002Fh3>\u003Cp>Used to debug specified processes, including reading and writing memory, commonly employed for DLL injection\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Col>\u003Cli>Locate a process with System privileges\u003C\u002Fli>\u003Cli>DLL injection\u003C\u002Fli>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeDebugPrivilege for the current process and injecting a DLL into a specified process\u003C\u002Fp>\u003Ch2>0x0C Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes exploitation methods for nine types of privileges in ordinary user (or LocalService user) Tokens, analyzes exploitation approaches, and refines implementation code\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previous articles \"Penetration Techniques - Switching from Admin to System Privileges\" and \"Penetration Techniques - Token Theft and Exploitation\" introduced methods to switch from admin privileges to system and TrustedInstaller privileges respectively, with the primary approach being token-based privilege switching.\u003C\u002Fp>\u003Cp>So, what exploitable methods exist for special tokens of regular users (or LocalService users)? Can privilege escalation be achieved? How to determine?\u003C\u002Fp>\u003Cp>This article will combine personal experience, reference multiple open-source tools and materials, attempt to summarize this technique, and share learning insights.\u003C\u002Fp>\u003Cp>Referenced open-source tools and materials:\u003C\u002Fp>\u003Cul>\u003Cli>Hot Potato: https:\u002F\u002Fgithub.com\u002Ffoxglovesec\u002FPotato\u003C\u002Fli>\u003Cli>PowerShell version Hot Potato: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FTater\u003C\u002Fli>\u003Cli>Rotten Potato: https:\u002F\u002Fgithub.com\u002Fbreenmachine\u002FRottenPotatoNG\u003C\u002Fli>\u003Cli>lonelypotato: https:\u002F\u002Fgithub.com\u002Fdecoder-it\u002Flonelypotato\u003C\u002Fli>\u003Cli>Juicy Potato: https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u003C\u002Fli>\u003Cli>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F01\u002F16\u002Fhot-potato\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F09\u002F26\u002Frotten-potato-privilege-escalation-from-service-accounts-to-system\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Brief exploitation approach\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTcbPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeBackupPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeRestorePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Brief Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. After gaining access to the target, check available privileges\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fpriv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example, the privileges a regular user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016711270_0_2fce7dd500-1.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an administrator user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016716189_1_44d2f30554-1.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an IIS user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721684_2_39f9f7bc1c-1.jpeg\">\u003C\u002Fp>\u003Cp>The 'Privilege Name' item indicates the privileges held, and 'State' indicates the status of the privilege. We can use the WinAPI AdjustTokenPrivileges to set the privilege to Disabled or Enabled\u003C\u002Fp>\u003Cp>Reference implementation code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling a specified privilege (SeDebugPrivilege) and viewing the current username and held privileges\u003C\u002Fp>\u003Ch3>2. If the following nine privileges are included, we can further exploit them\u003C\u002Fh3>\u003Cul>\u003Cli>SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>SeTcbPrivilege\u003C\u002Fli>\u003Cli>SeBackupPrivilege\u003C\u002Fli>\u003Cli>SeRestorePrivilege\u003C\u002Fli>\u003Cli>SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Users of IIS or SQL Server typically have SeImpersonatePrivilege and SeAssignPrimaryPrivilege permissions.\u003C\u002Fp>\u003Cp>Backup service users typically have SeBackupPrivilege and SeRestorePrivilege permissions.\u003C\u002Fp>\u003Ch2>0x03 Exploitation Ideas for SeImpersonatePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L327\u003C\u002Fp>\u003Ch3>SeImpersonatePrivilege\u003C\u002Fh3>\u003Cp>Impersonate a client after authentication\u003C\u002Fp>\u003Cp>Processes with this privilege can impersonate existing tokens but cannot create new tokens\u003C\u002Fp>\u003Cp>The following users have this privilege:\u003C\u002Fp>\u003Cul>\u003Cli>Local Administrators group members and local service accounts\u003C\u002Fli>\u003Cli>Services started by the Service Control Manager\u003C\u002Fli>\u003Cli>COM servers launched by the Component Object Model (COM) infrastructure and configured to run under a specific account\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically, IIS or SQL Server users have this privilege\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Obtain a System user token via NTLM Relay to Local Negotiation\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Can use open-source tools such as Rotten Potato, LonelyPotato, or Juicy Potato\u003C\u002Fp>\u003Col>\u003Cli>Create a new process using the WinAPI CreateProcessWithToken, passing the System user token\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Requires SeImpersonatePrivilege to succeed\u003C\u002Fp>\u003Col>\u003Cli>This token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeImpersonatePrivilege permission of the current process, calls CreateProcessWithToken, passes the current process's Token to create a process, and can be used with RottenPotato to escalate privileges from LocalService to System\u003C\u002Fp>\u003Ch2>0x04 Exploitation ideas for SeAssignPrimaryPrivilege permission\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L359\u003C\u002Fp>\u003Ch3>SeAssignPrimaryPrivilege\u003C\u002Fh3>\u003Cp>Assign a token to a process (newly created or suspended)\u003C\u002Fp>\u003Cp>Typically, iis or sqlserver users have this permission\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Use NTLM Relay to Local Negotiation to obtain the System user's Token\u003C\u002Fli>\u003Cli>Create a new process via WinAPI CreateProcessAsUser, passing the System user's Token\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeAssignPrimaryTokenPrivilege privilege for the current process, calls CreateProcessAsUser, passes the current process's Token to create a process, and combined with RottenPotato, can be used to escalate privileges from LocalService to System.\u003C\u002Fp>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain the System user's Token by exploiting NTLM Relay to Local Negotiation\u003C\u002Fli>\u003Cli>Create a suspended new process via the WinAPI CreateProcess, with the parameter set to CREATE_SUSPENDED\u003C\u002Fli>\u003Cli>Replace the new process's Token with the System user's Token via the WinAPI NtSetInformationProcess\u003C\u002Fli>\u003Cli>This Token possesses System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>Exploitation approach for the 0x05 SeTcbPrivilege privilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L418\u003C\u002Fp>\u003Ch3>SeTcbPrivilege\u003C\u002Fh3>\u003Cp>Equivalent to obtaining the highest system privileges\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Call LsaLogonUser to obtain a Token\u003C\u002Fli>\u003Cli>Add this Token to the Local System account group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeTcbPrivilege for the current process, logs in user test1, adds it to the Local System account group, obtains System privileges, and creates registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testtcb\u003C\u002Fp>\u003Ch2>0x06 Exploitation approach for SeBackupPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L495\u003C\u002Fp>\u003Ch3>SeBackupPrivilege\u003C\u002Fh3>\u003Cp>Used to perform backup operations, has read permissions for any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Read registry HKEY_LOCAL_MACHINE\\SAM, HKEY_LOCAL_MACHINE\\SECURITY, and HKEY_LOCAL_MACHINE\\SYSTEM\u003C\u002Fli>\u003Cli>Export all user hashes from the current system\u003C\u002Fli>\u003C\u002Fol>\u003Cp>mimikatz command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeBackupPrivilege of the current process, reading the registry, and saving it to files C:\\\\test\\\\SAM, C:\\\\test\\\\SECURITY, and C:\\\\test\\\\SYSTEM\u003C\u002Fp>\u003Ch2>0x07 Exploitation ideas for SeRestorePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L528\u003C\u002Fp>\u003Ch3>SeRestorePrivilege\u003C\u002Fh3>\u003Cp>Used to perform restore operations, granting write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege, modify the registry `HKLM\\SOFTWARE\\Microsoft\\Windows\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options`\u003C\u002Fp>\u003Col>\u003Cli>Hijack the startup of exe files\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation Idea 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege permission, write dll files to arbitrary paths\u003C\u002Fli>\u003Cli>Achieve dll hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeRestorePrivilege for the current process, creating the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testrestore\u003C\u002Fp>\u003Ch2>0x08 Exploitation Idea for SeCreateTokenPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L577\u003C\u002Fp>\u003Ch3>SeCreateTokenPrivilege\u003C\u002Fh3>\u003Cp>Used to create Primary Token\u003C\u002Fp>\u003Ch3>Exploitation idea\u003C\u002Fh3>\u003Col>\u003Cli>Create Primary Token via WinAPI ZwCreateToken\u003C\u002Fli>\u003Cli>Add Token to local administrator group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeCreateTokenPrivilege for the current process, creating a Primary Token, adding it to the local administrator group, and enabling SeDebugPrivilege and SeTcbPrivilege\u003C\u002Fp>\u003Ch2>0x09 SeLoadDriverPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L626\u003C\u002Fp>\u003Ch3>SeLoadDriverPrivilege\u003C\u002Fh3>\u003Cp>Used to load driver files\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Create registry entries for driver files\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv ImagePath \u002Ft REG_SZ \u002Fd \"\\??\\C:\\test\\Capcom.sys\"\u003Cbr>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Load driver file Capcom.sys\u003C\u002Fli>\u003Cli>Capcom.sys contains a vulnerability; after system loading, privileges can be escalated from ordinary user to System level. Reference exploit code:\u003C\u002Fli>\u003C\u002Fol>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftandasat\u002FExploitCapcom\u003C\u002Fp>\u003Col>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeLoadDriverPrivilege for the current process, reads registry key hkcu\\System\\CurrentControlSet\\CAPCOM, and loads driver file Capcom.sys\u003C\u002Fp>\u003Ch2>0x0A Exploitation approach for SeTakeOwnershipPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L688\u003C\u002Fp>\u003Ch3>SeTakeOwnershipPrivilege\u003C\u002Fh3>\u003Cp>Similar to SeRestorePrivilege, grants write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege, modify registry `HKLM\\SOFTWARE\\Microsoft\\Windows`\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options\u003C\u002Fp>\u003Col>\u003Cli>Hijacking EXE file startup\u003C\u002Fli>\u003Cli>Achieving privilege escalation or acting as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege permissions to write DLL files to arbitrary paths\u003C\u002Fli>\u003Cli>Implement DLL hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or act as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code enables SeTakeOwnershipPrivilege for the current process, modifies permissions for the registry key hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options, granting full operational permissions to standard user accounts\u003C\u002Fp>\u003Cp>Subsequent write operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\" \u002Fv takeownership \u002Ft REG_SZ \u002Fd \"C:\\\\Windows\\\\System32\\\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x0B SeDebugPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L736\u003C\u002Fp>\u003Ch3>SeDebugPrivilege\u003C\u002Fh3>\u003Cp>Used to debug specified processes, including reading and writing memory, commonly employed for DLL injection\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Col>\u003Cli>Locate a process with System privileges\u003C\u002Fli>\u003Cli>DLL injection\u003C\u002Fli>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeDebugPrivilege for the current process and injecting a DLL into a specified process\u003C\u002Fp>\u003Ch2>0x0C Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes exploitation methods for nine types of privileges in ordinary user (or LocalService user) Tokens, analyzes exploitation approaches, and refines implementation code\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",113,"Onedaysec",6,"published","2026-02-02T07:25:19.687Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exploiting Windows Privileges: 9 Techniques for Penetration Testing","Windows privileges, penetration testing, privilege escalation, SeImpersonatePrivilege, exploitation techniques, token theft, admin to system, local privilege escalation, security testing, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],1138,1136,1135,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.332Z","2026-07-23T16:02:34.806Z","draft","2026-07-23T16:16:57.046Z"]