[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYFulQfNF3nkpmeJrMXYX-H2jFN2a_J7kjBttu3WwpoM":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1138,"What can an attacker do with SeDebugPrivilege to escalate privileges or access sensitive processes?","SeDebugPrivilege allows a user to debug any process, including those running as SYSTEM, effectively granting the ability to read and write process memory. An attacker with this privilege can inject code into SYSTEM processes, steal tokens, or dump credentials. This is one of the nine exploitable privileges outlined in [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges), and it is often combined with techniques like [Penetration Techniques - Token Theft and Exploitation](\u002Fnews\u002Fpenetration-techniques-token-theft-and-exploitation).","\u003Cp>SeDebugPrivilege allows a user to debug any process, including those running as SYSTEM, effectively granting the ability to read and write process memory. An attacker with this privilege can inject code into SYSTEM processes, steal tokens, or dump credentials. This is one of the nine exploitable privileges outlined in [Penetration Techniques - Exploitation of Nine Windows Privileges](\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges), and it is often combined with techniques like [Penetration Techniques - Token Theft and Exploitation](\u002Fnews\u002Fpenetration-techniques-token-theft-and-exploitation).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-exploitation-of-nine-windows-privileges\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-can-an-attacker-do-with-sedebugprivilege-to-escalate-privileges-or-access-s-1777480365523","SeDebugPrivilege, process injection, token theft, credential dumping, debugging",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},276,"Penetration Techniques - Exploitation of Nine Windows Privileges","penetration-techniques-exploitation-of-nine-windows-privileges","Learn to exploit nine Windows privileges like SeImpersonatePrivilege for privilege escalation. Techniques include token theft, NTLM relay, and open-source tools for penetration testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previous articles \"Penetration Techniques - Switching from Admin to System Privileges\" and \"Penetration Techniques - Token Theft and Exploitation\" introduced methods to switch from admin privileges to system and TrustedInstaller privileges respectively, with the primary approach being token-based privilege switching.\u003C\u002Fp>\u003Cp>So, what exploitable methods exist for special tokens of regular users (or LocalService users)? Can privilege escalation be achieved? How to determine?\u003C\u002Fp>\u003Cp>This article will combine personal experience, reference multiple open-source tools and materials, attempt to summarize this technique, and share learning insights.\u003C\u002Fp>\u003Cp>Referenced open-source tools and materials:\u003C\u002Fp>\u003Cul>\u003Cli>Hot Potato: https:\u002F\u002Fgithub.com\u002Ffoxglovesec\u002FPotato\u003C\u002Fli>\u003Cli>PowerShell version Hot Potato: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FTater\u003C\u002Fli>\u003Cli>Rotten Potato: https:\u002F\u002Fgithub.com\u002Fbreenmachine\u002FRottenPotatoNG\u003C\u002Fli>\u003Cli>lonelypotato: https:\u002F\u002Fgithub.com\u002Fdecoder-it\u002Flonelypotato\u003C\u002Fli>\u003Cli>Juicy Potato: https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u003C\u002Fli>\u003Cli>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F01\u002F16\u002Fhot-potato\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F09\u002F26\u002Frotten-potato-privilege-escalation-from-service-accounts-to-system\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Brief exploitation approach\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTcbPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeBackupPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeRestorePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Brief Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. After gaining access to the target, check available privileges\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fpriv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example, the privileges a regular user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016711270_0_2fce7dd500.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an administrator user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016716189_1_44d2f30554.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an IIS user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721684_2_39f9f7bc1c.jpeg\">\u003C\u002Fp>\u003Cp>The 'Privilege Name' item indicates the privileges held, and 'State' indicates the status of the privilege. We can use the WinAPI AdjustTokenPrivileges to set the privilege to Disabled or Enabled\u003C\u002Fp>\u003Cp>Reference implementation code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling a specified privilege (SeDebugPrivilege) and viewing the current username and held privileges\u003C\u002Fp>\u003Ch3>2. If the following nine privileges are included, we can further exploit them\u003C\u002Fh3>\u003Cul>\u003Cli>SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>SeTcbPrivilege\u003C\u002Fli>\u003Cli>SeBackupPrivilege\u003C\u002Fli>\u003Cli>SeRestorePrivilege\u003C\u002Fli>\u003Cli>SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Users of IIS or SQL Server typically have SeImpersonatePrivilege and SeAssignPrimaryPrivilege permissions.\u003C\u002Fp>\u003Cp>Backup service users typically have SeBackupPrivilege and SeRestorePrivilege permissions.\u003C\u002Fp>\u003Ch2>0x03 Exploitation Ideas for SeImpersonatePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L327\u003C\u002Fp>\u003Ch3>SeImpersonatePrivilege\u003C\u002Fh3>\u003Cp>Impersonate a client after authentication\u003C\u002Fp>\u003Cp>Processes with this privilege can impersonate existing tokens but cannot create new tokens\u003C\u002Fp>\u003Cp>The following users have this privilege:\u003C\u002Fp>\u003Cul>\u003Cli>Local Administrators group members and local service accounts\u003C\u002Fli>\u003Cli>Services started by the Service Control Manager\u003C\u002Fli>\u003Cli>COM servers launched by the Component Object Model (COM) infrastructure and configured to run under a specific account\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically, IIS or SQL Server users have this privilege\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Obtain a System user token via NTLM Relay to Local Negotiation\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Can use open-source tools such as Rotten Potato, LonelyPotato, or Juicy Potato\u003C\u002Fp>\u003Col>\u003Cli>Create a new process using the WinAPI CreateProcessWithToken, passing the System user token\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Requires SeImpersonatePrivilege to succeed\u003C\u002Fp>\u003Col>\u003Cli>This token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeImpersonatePrivilege permission of the current process, calls CreateProcessWithToken, passes the current process's Token to create a process, and can be used with RottenPotato to escalate privileges from LocalService to System\u003C\u002Fp>\u003Ch2>0x04 Exploitation ideas for SeAssignPrimaryPrivilege permission\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L359\u003C\u002Fp>\u003Ch3>SeAssignPrimaryPrivilege\u003C\u002Fh3>\u003Cp>Assign a token to a process (newly created or suspended)\u003C\u002Fp>\u003Cp>Typically, iis or sqlserver users have this permission\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Use NTLM Relay to Local Negotiation to obtain the System user's Token\u003C\u002Fli>\u003Cli>Create a new process via WinAPI CreateProcessAsUser, passing the System user's Token\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeAssignPrimaryTokenPrivilege privilege for the current process, calls CreateProcessAsUser, passes the current process's Token to create a process, and combined with RottenPotato, can be used to escalate privileges from LocalService to System.\u003C\u002Fp>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain the System user's Token by exploiting NTLM Relay to Local Negotiation\u003C\u002Fli>\u003Cli>Create a suspended new process via the WinAPI CreateProcess, with the parameter set to CREATE_SUSPENDED\u003C\u002Fli>\u003Cli>Replace the new process's Token with the System user's Token via the WinAPI NtSetInformationProcess\u003C\u002Fli>\u003Cli>This Token possesses System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>Exploitation approach for the 0x05 SeTcbPrivilege privilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L418\u003C\u002Fp>\u003Ch3>SeTcbPrivilege\u003C\u002Fh3>\u003Cp>Equivalent to obtaining the highest system privileges\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Call LsaLogonUser to obtain a Token\u003C\u002Fli>\u003Cli>Add this Token to the Local System account group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeTcbPrivilege for the current process, logs in user test1, adds it to the Local System account group, obtains System privileges, and creates registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testtcb\u003C\u002Fp>\u003Ch2>0x06 Exploitation approach for SeBackupPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L495\u003C\u002Fp>\u003Ch3>SeBackupPrivilege\u003C\u002Fh3>\u003Cp>Used to perform backup operations, has read permissions for any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Read registry HKEY_LOCAL_MACHINE\\SAM, HKEY_LOCAL_MACHINE\\SECURITY, and HKEY_LOCAL_MACHINE\\SYSTEM\u003C\u002Fli>\u003Cli>Export all user hashes from the current system\u003C\u002Fli>\u003C\u002Fol>\u003Cp>mimikatz command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeBackupPrivilege of the current process, reading the registry, and saving it to files C:\\\\test\\\\SAM, C:\\\\test\\\\SECURITY, and C:\\\\test\\\\SYSTEM\u003C\u002Fp>\u003Ch2>0x07 Exploitation ideas for SeRestorePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L528\u003C\u002Fp>\u003Ch3>SeRestorePrivilege\u003C\u002Fh3>\u003Cp>Used to perform restore operations, granting write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege, modify the registry `HKLM\\SOFTWARE\\Microsoft\\Windows\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options`\u003C\u002Fp>\u003Col>\u003Cli>Hijack the startup of exe files\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation Idea 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege permission, write dll files to arbitrary paths\u003C\u002Fli>\u003Cli>Achieve dll hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeRestorePrivilege for the current process, creating the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testrestore\u003C\u002Fp>\u003Ch2>0x08 Exploitation Idea for SeCreateTokenPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L577\u003C\u002Fp>\u003Ch3>SeCreateTokenPrivilege\u003C\u002Fh3>\u003Cp>Used to create Primary Token\u003C\u002Fp>\u003Ch3>Exploitation idea\u003C\u002Fh3>\u003Col>\u003Cli>Create Primary Token via WinAPI ZwCreateToken\u003C\u002Fli>\u003Cli>Add Token to local administrator group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeCreateTokenPrivilege for the current process, creating a Primary Token, adding it to the local administrator group, and enabling SeDebugPrivilege and SeTcbPrivilege\u003C\u002Fp>\u003Ch2>0x09 SeLoadDriverPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L626\u003C\u002Fp>\u003Ch3>SeLoadDriverPrivilege\u003C\u002Fh3>\u003Cp>Used to load driver files\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Create registry entries for driver files\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv ImagePath \u002Ft REG_SZ \u002Fd \"\\??\\C:\\test\\Capcom.sys\"\u003Cbr>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Load driver file Capcom.sys\u003C\u002Fli>\u003Cli>Capcom.sys contains a vulnerability; after system loading, privileges can be escalated from ordinary user to System level. Reference exploit code:\u003C\u002Fli>\u003C\u002Fol>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftandasat\u002FExploitCapcom\u003C\u002Fp>\u003Col>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeLoadDriverPrivilege for the current process, reads registry key hkcu\\System\\CurrentControlSet\\CAPCOM, and loads driver file Capcom.sys\u003C\u002Fp>\u003Ch2>0x0A Exploitation approach for SeTakeOwnershipPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L688\u003C\u002Fp>\u003Ch3>SeTakeOwnershipPrivilege\u003C\u002Fh3>\u003Cp>Similar to SeRestorePrivilege, grants write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege, modify registry `HKLM\\SOFTWARE\\Microsoft\\Windows`\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options\u003C\u002Fp>\u003Col>\u003Cli>Hijacking EXE file startup\u003C\u002Fli>\u003Cli>Achieving privilege escalation or acting as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege permissions to write DLL files to arbitrary paths\u003C\u002Fli>\u003Cli>Implement DLL hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or act as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code enables SeTakeOwnershipPrivilege for the current process, modifies permissions for the registry key hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options, granting full operational permissions to standard user accounts\u003C\u002Fp>\u003Cp>Subsequent write operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\" \u002Fv takeownership \u002Ft REG_SZ \u002Fd \"C:\\\\Windows\\\\System32\\\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x0B SeDebugPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L736\u003C\u002Fp>\u003Ch3>SeDebugPrivilege\u003C\u002Fh3>\u003Cp>Used to debug specified processes, including reading and writing memory, commonly employed for DLL injection\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Col>\u003Cli>Locate a process with System privileges\u003C\u002Fli>\u003Cli>DLL injection\u003C\u002Fli>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeDebugPrivilege for the current process and injecting a DLL into a specified process\u003C\u002Fp>\u003Ch2>0x0C Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes exploitation methods for nine types of privileges in ordinary user (or LocalService user) Tokens, analyzes exploitation approaches, and refines implementation code\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Previous articles \"Penetration Techniques - Switching from Admin to System Privileges\" and \"Penetration Techniques - Token Theft and Exploitation\" introduced methods to switch from admin privileges to system and TrustedInstaller privileges respectively, with the primary approach being token-based privilege switching.\u003C\u002Fp>\u003Cp>So, what exploitable methods exist for special tokens of regular users (or LocalService users)? Can privilege escalation be achieved? How to determine?\u003C\u002Fp>\u003Cp>This article will combine personal experience, reference multiple open-source tools and materials, attempt to summarize this technique, and share learning insights.\u003C\u002Fp>\u003Cp>Referenced open-source tools and materials:\u003C\u002Fp>\u003Cul>\u003Cli>Hot Potato: https:\u002F\u002Fgithub.com\u002Ffoxglovesec\u002FPotato\u003C\u002Fli>\u003Cli>PowerShell version Hot Potato: https:\u002F\u002Fgithub.com\u002FKevin-Robertson\u002FTater\u003C\u002Fli>\u003Cli>Rotten Potato: https:\u002F\u002Fgithub.com\u002Fbreenmachine\u002FRottenPotatoNG\u003C\u002Fli>\u003Cli>lonelypotato: https:\u002F\u002Fgithub.com\u002Fdecoder-it\u002Flonelypotato\u003C\u002Fli>\u003Cli>Juicy Potato: https:\u002F\u002Fgithub.com\u002Fohpe\u002Fjuicy-potato\u003C\u002Fli>\u003Cli>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F01\u002F16\u002Fhot-potato\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2016\u002F09\u002F26\u002Frotten-potato-privilege-escalation-from-service-accounts-to-system\u002F\u003C\u002Fli>\u003Cli>https:\u002F\u002Ffoxglovesecurity.com\u002F2017\u002F08\u002F25\u002Fabusing-token-privileges-for-windows-local-privilege-escalation\u002F\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Brief exploitation approach\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTcbPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeBackupPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeRestorePrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>Exploitation approach and open-source code for SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Brief Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. After gaining access to the target, check available privileges\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>whoami \u002Fpriv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>For example, the privileges a regular user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016711270_0_2fce7dd500-1.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an administrator user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016716189_1_44d2f30554-1.jpeg\">\u003C\u002Fp>\u003Cp>The privileges an IIS user has are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721684_2_39f9f7bc1c-1.jpeg\">\u003C\u002Fp>\u003Cp>The 'Privilege Name' item indicates the privileges held, and 'State' indicates the status of the privilege. We can use the WinAPI AdjustTokenPrivileges to set the privilege to Disabled or Enabled\u003C\u002Fp>\u003Cp>Reference implementation code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling a specified privilege (SeDebugPrivilege) and viewing the current username and held privileges\u003C\u002Fp>\u003Ch3>2. If the following nine privileges are included, we can further exploit them\u003C\u002Fh3>\u003Cul>\u003Cli>SeImpersonatePrivilege\u003C\u002Fli>\u003Cli>SeAssignPrimaryPrivilege\u003C\u002Fli>\u003Cli>SeTcbPrivilege\u003C\u002Fli>\u003Cli>SeBackupPrivilege\u003C\u002Fli>\u003Cli>SeRestorePrivilege\u003C\u002Fli>\u003Cli>SeCreateTokenPrivilege\u003C\u002Fli>\u003Cli>SeLoadDriverPrivilege\u003C\u002Fli>\u003Cli>SeTakeOwnershipPrivilege\u003C\u002Fli>\u003Cli>SeDebugPrivilege\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Users of IIS or SQL Server typically have SeImpersonatePrivilege and SeAssignPrimaryPrivilege permissions.\u003C\u002Fp>\u003Cp>Backup service users typically have SeBackupPrivilege and SeRestorePrivilege permissions.\u003C\u002Fp>\u003Ch2>0x03 Exploitation Ideas for SeImpersonatePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L327\u003C\u002Fp>\u003Ch3>SeImpersonatePrivilege\u003C\u002Fh3>\u003Cp>Impersonate a client after authentication\u003C\u002Fp>\u003Cp>Processes with this privilege can impersonate existing tokens but cannot create new tokens\u003C\u002Fp>\u003Cp>The following users have this privilege:\u003C\u002Fp>\u003Cul>\u003Cli>Local Administrators group members and local service accounts\u003C\u002Fli>\u003Cli>Services started by the Service Control Manager\u003C\u002Fli>\u003Cli>COM servers launched by the Component Object Model (COM) infrastructure and configured to run under a specific account\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Typically, IIS or SQL Server users have this privilege\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Obtain a System user token via NTLM Relay to Local Negotiation\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Can use open-source tools such as Rotten Potato, LonelyPotato, or Juicy Potato\u003C\u002Fp>\u003Col>\u003Cli>Create a new process using the WinAPI CreateProcessWithToken, passing the System user token\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Requires SeImpersonatePrivilege to succeed\u003C\u002Fp>\u003Col>\u003Cli>This token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeImpersonatePrivilege permission of the current process, calls CreateProcessWithToken, passes the current process's Token to create a process, and can be used with RottenPotato to escalate privileges from LocalService to System\u003C\u002Fp>\u003Ch2>0x04 Exploitation ideas for SeAssignPrimaryPrivilege permission\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L359\u003C\u002Fp>\u003Ch3>SeAssignPrimaryPrivilege\u003C\u002Fh3>\u003Cp>Assign a token to a process (newly created or suspended)\u003C\u002Fp>\u003Cp>Typically, iis or sqlserver users have this permission\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Use NTLM Relay to Local Negotiation to obtain the System user's Token\u003C\u002Fli>\u003Cli>Create a new process via WinAPI CreateProcessAsUser, passing the System user's Token\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeAssignPrimaryTokenPrivilege privilege for the current process, calls CreateProcessAsUser, passes the current process's Token to create a process, and combined with RottenPotato, can be used to escalate privileges from LocalService to System.\u003C\u002Fp>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain the System user's Token by exploiting NTLM Relay to Local Negotiation\u003C\u002Fli>\u003Cli>Create a suspended new process via the WinAPI CreateProcess, with the parameter set to CREATE_SUSPENDED\u003C\u002Fli>\u003Cli>Replace the new process's Token with the System user's Token via the WinAPI NtSetInformationProcess\u003C\u002Fli>\u003Cli>This Token possesses System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>Exploitation approach for the 0x05 SeTcbPrivilege privilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L418\u003C\u002Fp>\u003Ch3>SeTcbPrivilege\u003C\u002Fh3>\u003Cp>Equivalent to obtaining the highest system privileges\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Call LsaLogonUser to obtain a Token\u003C\u002Fli>\u003Cli>Add this Token to the Local System account group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeTcbPrivilege for the current process, logs in user test1, adds it to the Local System account group, obtains System privileges, and creates registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testtcb\u003C\u002Fp>\u003Ch2>0x06 Exploitation approach for SeBackupPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L495\u003C\u002Fp>\u003Ch3>SeBackupPrivilege\u003C\u002Fh3>\u003Cp>Used to perform backup operations, has read permissions for any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Read registry HKEY_LOCAL_MACHINE\\SAM, HKEY_LOCAL_MACHINE\\SECURITY, and HKEY_LOCAL_MACHINE\\SYSTEM\u003C\u002Fli>\u003Cli>Export all user hashes from the current system\u003C\u002Fli>\u003C\u002Fol>\u003Cp>mimikatz command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>lsadump::sam \u002Fsam:SamBkup.hiv \u002Fsystem:SystemBkup.hiv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling the SeBackupPrivilege of the current process, reading the registry, and saving it to files C:\\\\test\\\\SAM, C:\\\\test\\\\SECURITY, and C:\\\\test\\\\SYSTEM\u003C\u002Fp>\u003Ch2>0x07 Exploitation ideas for SeRestorePrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L528\u003C\u002Fp>\u003Ch3>SeRestorePrivilege\u003C\u002Fh3>\u003Cp>Used to perform restore operations, granting write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation idea 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege, modify the registry `HKLM\\SOFTWARE\\Microsoft\\Windows\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options`\u003C\u002Fp>\u003Col>\u003Cli>Hijack the startup of exe files\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation Idea 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeRestorePrivilege permission, write dll files to arbitrary paths\u003C\u002Fli>\u003Cli>Achieve dll hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or serve as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeRestorePrivilege for the current process, creating the registry key HKEY_LOCAL_MACHINE\\SOFTWARE\\testrestore\u003C\u002Fp>\u003Ch2>0x08 Exploitation Idea for SeCreateTokenPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L577\u003C\u002Fp>\u003Ch3>SeCreateTokenPrivilege\u003C\u002Fh3>\u003Cp>Used to create Primary Token\u003C\u002Fp>\u003Ch3>Exploitation idea\u003C\u002Fh3>\u003Col>\u003Cli>Create Primary Token via WinAPI ZwCreateToken\u003C\u002Fli>\u003Cli>Add Token to local administrator group\u003C\u002Fli>\u003Cli>This Token has System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeCreateTokenPrivilege for the current process, creating a Primary Token, adding it to the local administrator group, and enabling SeDebugPrivilege and SeTcbPrivilege\u003C\u002Fp>\u003Ch2>0x09 SeLoadDriverPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L626\u003C\u002Fp>\u003Ch3>SeLoadDriverPrivilege\u003C\u002Fh3>\u003Cp>Used to load driver files\u003C\u002Fp>\u003Ch3>Exploitation approach\u003C\u002Fh3>\u003Col>\u003Cli>Create registry entries for driver files\u003C\u002Fli>\u003C\u002Fol>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv ImagePath \u002Ft REG_SZ \u002Fd \"\\??\\C:\\test\\Capcom.sys\"\u003Cbr>reg add hkcu\\System\\CurrentControlSet\\CAPCOM \u002Fv Type \u002Ft REG_DWORD \u002Fd 1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Col>\u003Cli>Load driver file Capcom.sys\u003C\u002Fli>\u003Cli>Capcom.sys contains a vulnerability; after system loading, privileges can be escalated from ordinary user to System level. Reference exploit code:\u003C\u002Fli>\u003C\u002Fol>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftandasat\u002FExploitCapcom\u003C\u002Fp>\u003Col>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Test code for reference:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeLoadDriverPrivilege for the current process, reads registry key hkcu\\System\\CurrentControlSet\\CAPCOM, and loads driver file Capcom.sys\u003C\u002Fp>\u003Ch2>0x0A Exploitation approach for SeTakeOwnershipPrivilege\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L688\u003C\u002Fp>\u003Ch3>SeTakeOwnershipPrivilege\u003C\u002Fh3>\u003Cp>Similar to SeRestorePrivilege, grants write permissions to any file on the current system\u003C\u002Fp>\u003Ch3>Exploitation approach 1\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege, modify registry `HKLM\\SOFTWARE\\Microsoft\\Windows`\u003C\u002Fli>\u003C\u002Fol>\u003Cp>NT\\CurrentVersion\\Image File Execution Options\u003C\u002Fp>\u003Col>\u003Cli>Hijacking EXE file startup\u003C\u002Fli>\u003Cli>Achieving privilege escalation or acting as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Ch3>Exploitation approach 2\u003C\u002Fh3>\u003Col>\u003Cli>Obtain SeTakeOwnershipPrivilege permissions to write DLL files to arbitrary paths\u003C\u002Fli>\u003Cli>Implement DLL hijacking\u003C\u002Fli>\u003Cli>Achieve privilege escalation or act as a backdoor\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code enables SeTakeOwnershipPrivilege for the current process, modifies permissions for the registry key hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options, granting full operational permissions to standard user accounts\u003C\u002Fp>\u003Cp>Subsequent write operation:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\" \u002Fv takeownership \u002Ft REG_SZ \u002Fd \"C:\\\\Windows\\\\System32\\\\calc.exe\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x0B SeDebugPrivilege exploitation approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FhatRiot\u002Ftoken-priv\u002Fblob\u002Fmaster\u002Fabusing_token_eop_1.0.txt#L736\u003C\u002Fp>\u003Ch3>SeDebugPrivilege\u003C\u002Fh3>\u003Cp>Used to debug specified processes, including reading and writing memory, commonly employed for DLL injection\u003C\u002Fp>\u003Ch3>Exploitation Approach\u003C\u002Fh3>\u003Col>\u003Cli>Locate a process with System privileges\u003C\u002Fli>\u003Cli>DLL injection\u003C\u002Fli>\u003Cli>Obtain System privileges\u003C\u002Fli>\u003C\u002Fol>\u003Cp>Reference test code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code implements enabling SeDebugPrivilege for the current process and injecting a DLL into a specified process\u003C\u002Fp>\u003Ch2>0x0C Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article summarizes exploitation methods for nine types of privileges in ordinary user (or LocalService user) Tokens, analyzes exploitation approaches, and refines implementation code\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",113,"Onedaysec",6,"published","2026-02-02T07:25:19.687Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Exploiting Windows Privileges: 9 Techniques for Penetration Testing","Windows privileges, penetration testing, privilege escalation, SeImpersonatePrivilege, exploitation techniques, token theft, admin to system, local privilege escalation, security testing, Windows security",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],1137,1136,1135,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.332Z","2026-07-23T16:02:34.806Z","draft","2026-07-23T16:16:57.394Z"]