Header
(Ab)using scheduled tasks to elevate privileges
In this example we obtained local admin on the box, but wanted domain admin instead. Craig quickly spotted that a scheduled task runs as domain admin (ntbackup). We hoped to simply change the backup params to give us a shell but this was hopeless, and if you try replacing the the ntbackup executable with a simple cmd.exe windows file protection stops us. The simple solution was to let the scheduled task run, debug the process and insert our cmd process in its memory space. (if your attacker already has local admin.. you have issues..) This video shows the attack under the debugger.. (post 2 probably does more of the explaining)
Blog
Video
Research
QotW
Categories
Old Videos

Videos RSS Feed
Conditions of use Privacy statement
Top of Page Legal stuff