Giter VIP home page Giter VIP logo

Comments (2)

HarmJ0y avatar HarmJ0y commented on August 20, 2024

So it's failing at the Helpers.GetSystem() call (https://github.com/GhostPack/Rubeus/blob/master/Rubeus/lib/Helpers.cs#L82-L134) . For some reason the token duplication method to elevate to SYSTEM is failing. This can occasionally happen in some situations where SeDebugPrivilege is removed from local administrators, but without the system to experiment with it's hard to tell.

Can you try to elevate to SYSTEM manually (i.e. with PSEXEC) and try running the same Rubeus command while running from that context?

from rubeus.

Wolchara000 avatar Wolchara000 commented on August 20, 2024

Ok. Done.
From "nt authority\system" it works fine.
Strange. I used clean Win 10 distr. + DC 2012R2 clean with domain as test environment. On both systems it didn't get monitor mode.

`C:>whoami
nt authority\system

C:>Rubeus.exe monitor


(_____ \ | |
) ) | | _____ _ _ ___
| __ /| | | | _ | ___ | | | |/
)
| | \ | || | |) ) | || | |
|| ||/|/|_____)_/(/

v1.5.0

[] Action: TGT Monitoring
[
] Monitoring every 60 seconds for new TGTs

[*] 15.04.2020 9:39:06 UTC - Found new TGT:

User : [email protected]
StartTime : 15.04.2020 10:44:00
EndTime : 15.04.2020 20:44:00
RenewTill : 22.04.2020 10:44:00
Flags : name_canonicalize, pre_authent, initial, renewable, forwardable
Base64EncodedTicket :

doIFLDCCBSigAwIBBaEDAgEWooIEMDCCBCxhggQoMIIEJKADAgEFoQ8bDVRIVU5URVIuTE9DQUyiIjAgoAMCAQKhGTAXGwZrcmJ0`

from rubeus.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.