Releases: wh0amitz/KRBUACBypass
Releases · wh0amitz/KRBUACBypass
KRBUACBypass
Now let's take a look at the running effect, as shown in the figure below. First request a ticket for the HOST service of the current server through the asktgs function, and then create a system service through krbscm to gain the SYSTEM privilege.
![Animation](https://private-user-images.githubusercontent.com/60350435/257920520-01b10da6-fd4e-4ac7-a20a-5fba97594721.gif?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3Mzk5OTM1OTEsIm5iZiI6MTczOTk5MzI5MSwicGF0aCI6Ii82MDM1MDQzNS8yNTc5MjA1MjAtMDFiMTBkYTYtZmQ0ZS00YWM3LWEyMGEtNWZiYTk3NTk0NzIxLmdpZj9YLUFtei1BbGdvcml0aG09QVdTNC1ITUFDLVNIQTI1NiZYLUFtei1DcmVkZW50aWFsPUFLSUFWQ09EWUxTQTUzUFFLNFpBJTJGMjAyNTAyMTklMkZ1cy1lYXN0LTElMkZzMyUyRmF3czRfcmVxdWVzdCZYLUFtei1EYXRlPTIwMjUwMjE5VDE5MjgxMVomWC1BbXotRXhwaXJlcz0zMDAmWC1BbXotU2lnbmF0dXJlPTg4ZjkzZWUzOWRkNjkxZTRhMDI4OTM0NDViYzQ2ZTkxMGE4ZGEyYmM2MTAzNzQ4OWQwNjUzYTVhZDk1ODNjNDAmWC1BbXotU2lnbmVkSGVhZGVycz1ob3N0In0.n-I2K0udY-Mj_QUM7175zuRAKe7zSkhNongCHT1Yhw0)