Penetration Testing mailing list archives

Re: [PEN-TEST] Expand right under Win2K


From: Reinder Wiersma <reinder.wiersma () CMG NL>
Date: Wed, 7 Feb 2001 11:25:28 +0100

Robin,

De andere mogelijkheid om Admin te worden staat op:
http://www.atstake.com/research/advisories/2001/index.html#020501-1
Ik ga dit nog verder uitzoeken.

Reinder.

-----Original Message-----
From: Gary Flynn [mailto:flynngn () JMU EDU]
Sent: dinsdag 6 februari 2001 18:07
To: PEN-TEST () SECURITYFOCUS COM
Subject: Re: [PEN-TEST] Expand right under Win2K


We have a win2k where we have access to a cmd.exe with the rights of the
web-server and we would like to obtain administrator rights. Also we
don't have the rights to read the SAM files.
We tried the well-known methdos under win  NT 4.0 (like breaknt.exe,
read from raw device) in vain.
Has anyone any idea what to be next step to administrator rights?

It looks like a new approach has just been made available....

http://www.microsoft.com/technet/security/bulletin/MS01-007.asp

--

Gary Flynn
Security Engineer - Technical Services
James Madison University

Please R.U.N.S.A.F.E.
http://www.jmu.edu/computing/info-security/engineering/runsafe.shtml


Current thread: