Friday, 27 May 2011

Get administrative privileges form your guest account


Get administrative privileges form your guest account

I think this hack will defiantly helpful for the collage students. College students generally don't have Administration privileges on lab computers to copy or install applications where they use this hack to gain some real stuff done on PC.


Windows command line task scheduler supports interactive mode which works somewhat same as sudo -i or su -i command in Linux/UNIX the only problem is that it does not ask you for password. This vulnerability is patched up in further versions of Windows than XP and works fine even in XP-3.


Press win+r or open  run type cmd hit enter and open command prompt and type

and note the time, time will be presented in 24 hour clock format. Note this time.
Now open “Task Manager” by typing

now from processes and end explorer.exe .

Now type,

c:\>at [(time displayed in 24 hour clock format)+2 minutes] /interactive cmd.exe
for example
The current time is: 0:27:11.68        
Enter the new time:


c:\>at 0:29:00:00 /interactive cmd.exe
Now type c:\>exit

And wait for two minutes. After two minutes command prompt will open in interactive mode with all administrative privileges without asking you for password. Now run any command from it it'll run with full administrative privileges so that you can even install programs and applications in system. So type “explorer.exe” in cmd and use system with administrative privilege even when you are in guest account.

Countermeasure:  Disable command prompt for guest account.

By the way no college can ever disable command prompt because practicals are done over it, so guys get your stance and enjoy freedom.


No comments:

Post a Comment