Can I read Exploiting NTFS Junctions for Privilege Escalation on EtoBox?
Exploiting NTFS Junctions for Privilege Escalation by Irvin.Joker is a document available to read on EtoBox.
What is Exploiting NTFS Junctions for Privilege Escalation about?
This document discusses privilege escalation through abusing privileged file operations. It provides examples of how unprivileged users can control files accessed by privileged processes. This can allow arbitrary code execution if the privileged process loads a user-controlled file as a library. Specific techniques discussed include using NTFS junctions and symlinks to redirect privileged processes to open files in controlled locations. Monitoring tools like Process Monitor are recommended to find vulnerabl
- Author
- Irvin.Joker
- Language
- EN