Login Register


[Q] Bypass blocked commands in cmd filter_list
Author
Message
[Q] Bypass blocked commands in cmd #1
Hello!
I have a small problem:
I found a computer, which had an admin account, and a user, without password.
I tried guessing the admin password, and the Oph cracker, but it does not seem to work.

Some commands are blocked on the guest account, which prevents me from creating a new admin user or password for the already existing one.

Is there a way to bypass the command restrictions?
(I can access the cmd itself)

The OS running is Win 7.

Any ideas on this?

Reply

RE: [Q] Bypass blocked commands in cmd #2
Place something like a RAT on the computer and try to use it to control the computer from another one.

Reply

RE: [Q] Bypass blocked commands in cmd #3
(09-27-2013, 10:55 PM)Screamz Wrote: Place something like a RAT on the computer and try to use it to control the computer from another one.

Wouldn't it still be with the rights of normal user, and not admin?

Reply

RE: [Q] Bypass blocked commands in cmd #4
(09-27-2013, 10:55 PM)Screamz Wrote: Place something like a RAT on the computer and try to use it to control the computer from another one.

You're stupid.
Try this, OP. You're gonna need a way to get Meterpreter on a box but that shouldn't be too hard.
If there's a version of this that's not a Metasploit module, I don't care enough to find it so you're on your own.
https://www.rapid7.com/db/modules/exploi...latten_rec
CVE: http://cvedetails.com/cve/2013-3660

(09-27-2013, 11:30 PM)CamIce Wrote: Wouldn't it still be with the rights of normal user, and not admin?

Yes. That guy's stupid.
(This post was last modified: 09-28-2013, 01:53 AM by Reiko.)
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply

RE: [Q] Bypass blocked commands in cmd #5
(09-28-2013, 01:51 AM)Starfall Wrote: You're stupid.
Try this, OP. You're gonna need a way to get Meterpreter on a box but that shouldn't be too hard.
If there's a version of this that's not a Metasploit module, I don't care enough to find it so you're on your own.
https://www.rapid7.com/db/modules/exploi...latten_rec
CVE: http://cvedetails.com/cve/2013-3660


Yes. That guy's stupid.


Thanks a lot for help. Going to try this right away.

Reply

RE: [Q] Bypass blocked commands in cmd #6
Could you possibly write the commands you need into a batch(.bat) file and run it?

Reply

RE: [Q] Bypass blocked commands in cmd #7
(09-28-2013, 01:51 AM)Starfall Wrote: You're stupid.
Try this, OP. You're gonna need a way to get Meterpreter on a box but that shouldn't be too hard.
If there's a version of this that's not a Metasploit module, I don't care enough to find it so you're on your own.
https://www.rapid7.com/db/modules/exploi...latten_rec
CVE: http://cvedetails.com/cve/2013-3660


Yes. That guy's stupid.

Actually, In the past, I have had them gain administrative rights, I'm not saying that it is going to work, but it was a suggestion.

Reply

RE: [Q] Bypass blocked commands in cmd #8
(09-28-2013, 03:06 PM)Dogs Toy Wrote: Could you possibly write the commands you need into a batch(.bat) file and run it?

Hmmm. didn't think about it. Thanks for suggestion. I got admin rights by using the exploit suggested above, but I will try this too for the purpose of learning :d

Reply

RE: [Q] Bypass blocked commands in cmd #9
Puppy linux

cp /WINDERS/Windows/System32/cmd.exe /WINDERS/Windows/System32/osk.exe

Try to open the on-screen keyboard from the login screen

net user <change password or create new admin>

Reply

RE: [Q] Bypass blocked commands in cmd #10
(09-29-2013, 02:01 AM)w00t Wrote: Puppy linux

cp /WINDERS/Windows/System32/cmd.exe /WINDERS/Windows/System32/osk.exe

Try to open the on-screen keyboard from the login screen

net user <change password or create new admin>

You misunderstood the question. Command Prompt wasn't disabled, OP just had very low rights.
PGP
Sign: F202 79C9 76F7 40BB 54EC 494F 5DEF 1D70 14C1 C4CC
Encrypt: A5B3 1B21 55E1 80AF 4C6E DE83 467B 8EFC 3DEE 681C
Auth: CD55 E8A5 1A08 2933 8BA6 BC88 D81F 1943 739A 3C47

Reply







Users browsing this thread: