Windows XP Local Privilege Escalation

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
1,192
Loading...
Alert icon
Sign in or sign up now!
Alert icon

Uploaded by on Apr 27, 2011

A little trick in windows XP to gain system level rights from a local limited rights account. Helpful if youve locked yourself out of an admin account and a variety of other reasons... such as adding programs or scripts to other user accounts from a local account.
Its just something I found not a lot of people know about but is useful.

Excuse the quality, it was bad enough on my phone but then youtube couldnt handle a 3gp so I had to re-encode to avi, and it was re-encoded to youtube from that. :\
Enjoy anyway.

Commands:
at xx:xx /interactive cmd.exe
(where xx:xx = local time +1 minute in 24 hour format)

  • likes, 0 dislikes

Link to this comment:

Share to:

Uploader Comments (systemerror11)

  • the problem i had with this is after a few second the program closes.

    When i rebooted the system, windows recognized the error and blocked execution.

  • @bmw2go11 you dont reboot, you close explorer.exe and execute it again from svchost.

  • can or will this be patched?

  • @xKargatx To the best of my knowledge its not patched, and that being the case its existed for years so I dont forsee it happening.

  • can this be done on windows 7

  • @putzamoale99 No.

Top Comments

  • Dear college, you're fucked.

  • @anonofsussex TASKMGR -> enter in cmd

see all

All Comments (17)

Sign In or Sign Up now to post a comment!
  • i get access denied.

  • are you a wizard

  • Aww I was gonna do this at college.

    1) Open command prompt

    I can do this by making a .bat in notepad on the college PCs

    2) Add one minute etc etc

    Yep, this too

    3) Open the task manager

    Damn. The college PC's don't let you open the task manager. Is it possible to open the task manager using notepad in any way?

  • Konboot is a great boot disc that let's one login to "any" account (with a password) without having to type a password. Just need physical access. Great for white hat needs.

  • @systemerror11 maybe it's only my setup, but my normal user doesn't have the permission to use the "at" command. I didn't try with the guest account, but if my user isn't allowed to then I guess the guest account can't ether.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more