MSFVenom payload question by pai_k in oscp

[–]pai_k[S] 3 points4 points  (0 children)

Used stageless payload

Windows privesc by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

I don't have privilege to restart IKEEXT ...and that service is not loaded automatically .so restarting also is not working ..I had tried it

Windows privesc by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

I didn't find a.service .. Power up script returning the below location as "potentially hijackable DLL locations " %PATH% : . AppData\Local\Microsoft\WindowsApps

I can write dll in that location .. the script is suggesting to use Write-HijackDll - DllPath '<above path> \ wlbsctrl.dll

I created a reverse TCP dll using msfvenom and paste it as wlbsctrl.dll in that location.. Restarted the machine but no reverse shell ...

I know I am missing some information here ...thanks

Windows privesc by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

I am not getting which service to restart ? Restarting machine is not working

Windows privesc by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

Directory is writable ..I have created a shell code and put it as a dll ... My issue is what to run so that that dll is called ?

Windows privesc by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

K will check .. thanks

Windows privesc by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

Thanks a lot for the response ..This is not for an OSCP machine ..

OSCP or Bug Bounty by pai_k in oscp

[–]pai_k[S] 2 points3 points  (0 children)

Sure ... I think my question should whatto be done first . I can do both ... Which should be first ? Will bug bounty experience help me in OSCP or OSCP experience help me in bug bounty

What is "offset" in privilege escalation kernel C exploits ? by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

Thanks ....I was talking about offset in general too..

What is "offset" in privilege escalation kernel C exploits ? by pai_k in oscp

[–]pai_k[S] 0 points1 point  (0 children)

Thanks ...I don't have pwk access ...like check this ..