编写提权EXP的时候经常用到这个功能,我把它封装成了一个函数,直接调用即可!
效果图:
源码:
void execute_command(int argc, _TCHAR* argv[])
{
if (argc <= 1)
{
printf("Usage:exp.exe ipconfig\n");
return;
}
HANDLE hReadPipe = NULL;
HANDLE hWritePipe = NULL;
SECURITY_ATTRIBUTES sa;
sa.nLength = sizeof(SECURITY_ATTRIBUTES); // 结构体的大小,可用SIZEOF取得
sa.lpSecurityDescriptor = NULL;//安全描述符
sa.bInheritHandle = TRUE;; // 安全描述的对象能否被新创建ÆÆ的进程继承
// Create anoymous pipe:
if (CreatePipe(&hReadPipe, &hWritePipe, &sa, 0) == NULL)
{
printf("Create anoymous pipe failed\n");
}
// Create Child Process:
PROCESS_INFORMATION pInfo = { 0 };
STARTUPINFO stInfo = { 0 };
stInfo.cb = sizeof(STARTUPINFO);
stInfo.dwFlags = STARTF_USESHOWWINDOW | STARTF_USESTDHANDLES;
stInfo.hStdOutput = hWritePipe;
stInfo.hStdError = hWritePipe;
// get
wchar_t cmd_buf[4096] = { 0 };
swprintf_s(cmd_buf,4096,L"/c %s", argv[1], wcslen(argv[1]));
if (!CreateProcess(L"c:\\windows\\system32\\cmd.exe", cmd_buf, NULL, NULL, TRUE, 0, NULL, NULL, &stInfo, &pInfo))
{
printf("Create child process failed!\n");
CloseHandle(hWritePipe);
CloseHandle(hReadPipe);
}
CloseHandle(hWritePipe);
// command buffer
char lpBuffer[4096];
DWORD lpBytesRead = 0;
while (PeekNamedPipe(hReadPipe, lpBuffer, 4096, &lpBytesRead, NULL, NULL))
{
if (lpBytesRead)
{
ReadFile(hReadPipe, lpBuffer, lpBytesRead, &lpBytesRead, NULL);
lpBuffer[lpBytesRead] = '\0';
printf("%s", lpBuffer);
}
}
WaitForSingleObject(pInfo.hProcess, INFINITE);
CloseHandle(hReadPipe);
}
使用方法:
int _tmain(int argc, _TCHAR* argv[])
{
execute_command(argc, argv);
}