Tuesday, May 7, 2013

Admin Escalation

1. Search the executable files of utility manager and command line console namely “Utilman.exe” & “Cmd.exe” in your windows’ system32 folder;
2. Backup and remove (or rename) your utility manager executable file;
3. Copy and paste and rename your command line executable file into “Utilman.exe”
4. Restart your computer and trigger the command line by pressing “Windows + U” before logging into the domain.
5. Launch the Computer Manager by typing “compmgmt.msc”
6. Adjust your current login into the Local Administrator group, done!
7. If, folder permission is limited, try another OS (e.g. Linux on a thumb drive) to start up the computer and edit the file mentioned in #3.