Obj 5 Local Priv Esc
Task - Elevate local privs on studentvm, Identify where we have local admin access.
We will be using PowerUp.ps1 for this objective
Find Unquoted service paths
Find service files we can modify
Find services we can modify
Abuse a service we found to be modifiable
Once we abuse this service we need to log off and back on for the escalation to take affect.
Find where we have local admin access
We can now use winrs or PSSremoting to access any machines listed from the command above.
PSSremote into another machine as local admin
Jenkins....
Coming soon...
Last updated