| View previous topic :: View next topic |
| Author |
Message |
Dark Byte Site Admin
Reputation: 471
Joined: 09 May 2003 Posts: 25860 Location: The netherlands
|
Posted: Fri Sep 07, 2012 4:30 pm Post subject: Granting file access and other privileges to process/thread |
|
|
Just asking if someone already dealt with this.
I have a process that has been launched by a user with limited rights (e.g. Deny on all disk access)
How can I inject a thread with the same privileges as the injector? Or at least file access to one particular file
Thread creation and api calls work fine , just file access is mostly access denied
Some ideas,
lpThreadAttributes in createRemoteThread
ImpersonateLoggedOnUser
SetThreadToken
Other acl crap
So yeah, just wondering if someone has already done this
Also, the process can not be restarted
edit2: I know I can just force load the file I wish into the target process, but i'm trying to do it in a 'legit' way this time
_________________
Do not ask me about online cheats. I don't know any and wont help finding them.
Like my help? Join me on Patreon so i can keep helping |
|
| Back to top |
|
 |
atom0s Moderator
Reputation: 205
Joined: 25 Jan 2006 Posts: 8587 Location: 127.0.0.1
|
Posted: Fri Sep 07, 2012 6:54 pm Post subject: |
|
|
Perhaps call RtlAdjustPrivilege and see if you can modify the privileges of your thread.
Not sure if the system has any security checks in place to prevent a limited user from doing this though, never had to launch anything like this.
An idea to bypass ACL would be to use RtlAdjustPrivilege and try using the SeTakeOwnershipPrivilege option as the first param.
After that, using RtlAdjustPrivilege with SeBackupPrivilege should let you access files.
_________________
- Retired. |
|
| Back to top |
|
 |
Dark Byte Site Admin
Reputation: 471
Joined: 09 May 2003 Posts: 25860 Location: The netherlands
|
Posted: Fri Sep 07, 2012 9:25 pm Post subject: |
|
|
Ok, some more checking. This process is running at Untrusted Mandatory Level
Perhaps I can change that from a admin level
_________________
Do not ask me about online cheats. I don't know any and wont help finding them.
Like my help? Join me on Patreon so i can keep helping |
|
| Back to top |
|
 |
|