r4wd3r/RID-Hijacking: Windows RID Hijacking persistence technique
2019-08-18 16:59:18 Author: github.com(查看原文) 阅读量:247 收藏

Join GitHub today

GitHub is home to over 40 million developers working together to host and review code, manage projects, and build software together.

Sign up

Arsenal

The RID Hijacking hook, applicable to all Windows versions, allows setting desired privileges to an existent account in a stealthy manner by modifying some security attributes of an user.

By only using OS resources, it is possible to replace the RID of an user right before the primary access token is created, allowing to spoof the privileges of the hijacked RID owner.

Modules

Slides

Derbycon 8.0

References

r4wsecurity: RID Hijacking - Maintaining access on Windows Machines


文章来源: https://github.com/r4wd3r/RID-Hijacking
如有侵权请联系:admin#unsafe.sh