Local Privileges Escalation in WinXP

Did you know that you can escalate you can become the SYSTEM user on a WinXP box simply by using the at command? Try this at home:

at 11:45pm /interactive cmd.exe

You just scheduled a job that will pop up a new cmd window exactly at 11:45pm. Who is the parent of this window? Why SYSTEM of course. But we are not done yet.

Have the new cmd window up? Good. Now kill explorer.exe using the Task Manager. Yes, just kill it! Keep the new cmd window open though. Use it to run explorer again by typing in explorer.exe. Done!

You are now logged in as SYSTEM. You can now go ahead and do all the nifty admin things that you always wanted to do but your IT department wouldn’t let you. ) You might get in trouble when they find out though. So, don’t go crazy with your newfound power.

If you still don’t believe me, here is a video that shows you how it’s done.

Related Posts:

  • How do you lock down XP Home?
  • Why you should not be excited about Vista
  • MySQL Reference
  • Bush Hid the Facts
  • Rails: #28000Access denied
  • WinXP Home Box Administration
  • Dell no longer ships WinXP CD’s with laptops?
  • PS3 Line Squatters
  • Blinking Dash Update And The Wisdom of Yahoo Answers
  • Windows XP Home: Running as a User

  • One Response to “Local Privileges Escalation in WinXP”

    1. Gravatar Terminally Incoherent » Blog Archive » How do you lock down XP Home? UNITED STATES Says: Reply to this comment

      […] In lieu of the privilege escalation hax I started to wonder what exactly do you need to do to lock down an XP Home machine. In XP pro you can use the group policies to limit what user can do on the local machine. Unfortunately, the home edition is missing gpedit.msc so we can only rely on registry hacks. […]

      Posted using WordPress WordPress 2.0.2

    Leave a Reply

    XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <pre lang=""> <em> <i> <strike> <strong>

    [Quote selected]