2790 lines
167 KiB
Plaintext
2790 lines
167 KiB
Plaintext
ANSI color bit for Windows is not set. If you are executing this from a Windows terminal inside the host you should run 'REG ADD HKCU\Console /v VirtualTerminalLevel /t REG_DWORD /d 1' and then start a new CMD
|
||
Long paths are disabled, so the maximum length of a path supported is 260 chars (this may cause false negatives when looking for files). If you are admin, you can enable it with 'REG ADD HKLM\SYSTEM\CurrentControlSet\Control\FileSystem /v VirtualTerminalLevel /t REG_DWORD /d 1' and then start a new CMD
|
||
[34m
|
||
[1;32m((((((((((((((((((((((((((((((((
|
||
[1;32m(((((((((((((((((((((((((((((((((((((((((((
|
||
[1;32m(((((((((((((([34m**********/[1;32m##########[1;32m(((((((((((((
|
||
[1;32m(((((((((((([34m********************/[1;32m#######[1;32m(((((((((((
|
||
[1;32m(((((((([34m******************[0m/@@@@@/[1;32m[34m****[1;32m######[1;32m((((((((((
|
||
[1;32m(((((([34m********************[0m@@@@@@@@@@/[1;32m[34m***,[1;32m####[1;32m((((((((((
|
||
[1;32m((((([34m********************[0m/@@@@@%@@@@/[1;32m[34m********[1;32m##[1;32m(((((((((
|
||
[1;32m((([1;32m############[34m*********[0m/%@@@@@@@@@/[1;32m[34m************[1;32m((((((((
|
||
[1;32m(([1;32m##################(/[34m******[0m/@@@@@/[1;32m[34m***************[1;32m((((((
|
||
[1;32m(([1;32m#########################(/[34m**********************[1;32m(((((
|
||
[1;32m(([1;32m##############################(/[34m*****************[1;32m(((((
|
||
[1;32m(([1;32m###################################(/[34m************[1;32m(((((
|
||
[1;32m(([1;32m#######################################([34m*********[1;32m(((((
|
||
[1;32m(([1;32m#######(,.***.,(###################(..***.[34m*******[1;32m(((((
|
||
[1;32m(([1;32m#######*(#####((##################((######/([34m*****[1;32m(((((
|
||
[1;32m(([1;32m###################(/***********(##############([1;32m)(((((
|
||
[1;32m((([1;32m#####################/*******(################[1;32m)((((((
|
||
[1;32m(((([1;32m############################################[1;32m)((((((
|
||
[1;32m((((([1;32m##########################################[1;32m)(((((((
|
||
[1;32m(((((([1;32m########################################[1;32m)(((((((
|
||
[1;32m(((((((([1;32m####################################[1;32m)((((((((
|
||
[1;32m((((((((([1;32m#################################[1;32m)(((((((((
|
||
[1;32m(((((((((([1;32m##########################[1;32m)(((((((((
|
||
[1;32m((((((((((((((((((((((((((((((((((((((
|
||
[1;32m(((((((((((((((((((((((((((((([0m
|
||
|
||
[1;33mADVISORY: [34mwinpeas should be used for authorized penetration testing and/or educational purposes only.Any misuse of this software will not be the responsibility of the author or of any other collaborator. Use it at your own devices and/or with the device owner's permission.
|
||
|
||
[33m WinPEAS-ng[0m[33m by @carlospolopm[0m
|
||
[1;32m
|
||
/---------------------------------------------------------------------------------\
|
||
| [34mDo you like PEASS?[1;32m |
|
||
|---------------------------------------------------------------------------------|
|
||
| [33mGet the latest version[1;32m : [1;31mhttps://github.com/sponsors/carlospolop[1;32m |
|
||
| [33mFollow on Twitter[1;32m : [1;31m@carlospolopm[1;32m |
|
||
| [33mRespect on HTB[1;32m : [1;31mSirBroccoli [1;32m |
|
||
|---------------------------------------------------------------------------------|
|
||
| [34mThank you![1;32m |
|
||
\---------------------------------------------------------------------------------/
|
||
[0m
|
||
[33m [+] [1;32mLegend:[0m
|
||
[1;31m Red[1;37m Indicates a special privilege over an object or something is misconfigured[0m
|
||
[1;32m Green[1;37m Indicates that some protection is enabled or something is well configured[0m
|
||
[36m Cyan[1;37m Indicates active users[0m
|
||
[34m Blue[1;37m Indicates disabled users[0m
|
||
[1;33m LightYellow[1;37m Indicates links[0m
|
||
|
||
[34m You can find a Windows local PE Checklist here: [33mhttps://book.hacktricks.xyz/windows-hardening/checklist-windows-privilege-escalation
|
||
[1;90m Creating Dynamic lists, this could take a while, please wait...[0m
|
||
[1;90m - Loading sensitive_files yaml definitions file...[0m
|
||
[1;90m - Loading regexes yaml definitions file...[0m
|
||
[1;90m - Checking if domain...[0m
|
||
[1;90m - Getting Win32_UserAccount info...[0m
|
||
[1;90m - Creating current user groups list...[0m
|
||
[1;90m [X] Exception: Object reference not set to an instance of an object.[0m
|
||
[1;90m [X] Exception: Object reference not set to an instance of an object.[0m
|
||
[1;90m - Creating active users list (local only)...[0m
|
||
[1;90m - Creating disabled users list...[0m
|
||
[1;90m - Admin users list...[0m
|
||
[1;90m - Creating AppLocker bypass list...[0m
|
||
[1;90m - Creating files/directories list for search...[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSystem Information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mBasic System Information[0m
|
||
[1;36m<36> [1;34mCheck if the Windows versions is vulnerable to some known exploit [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#kernel-exploits[0m
|
||
[1;37m Hostname: [0mg0
|
||
[1;37m Domain Name: [0mflight.htb
|
||
[1;37m ProductName: [0mWindows Server 2019 Standard
|
||
[1;37m EditionID: [0mServerStandard
|
||
[1;37m ReleaseId: [0m1809
|
||
[1;37m BuildBranch: [0mrs5_release
|
||
[1;37m CurrentMajorVersionNumber: [0m10
|
||
[1;37m CurrentVersion: [0m6.3
|
||
[1;37m Architecture: [0mAMD64
|
||
[1;37m ProcessorCount: [0m2
|
||
[1;37m SystemLang: [0men-US
|
||
[1;37m KeyboardLang: [0mEnglish (United States)
|
||
[1;37m TimeZone: [0m(UTC-08:00) Pacific Time (US & Canada)
|
||
[1;37m IsVirtualMachine: [0m[0m[1;31mTrue[0m
|
||
[1;37m Current Time: [0m2/9/2023 10:25:50 AM
|
||
[1;37m HighIntegrity: [0mFalse
|
||
[1;37m PartOfDomain: [0m[0m[1;31mTrue[0m
|
||
[1;37m Hotfixes: [0m[1;32m[0m
|
||
|
||
[33m [?] [1;34mWindows vulns search powered by [1;31mWatson[1;34m(https://github.com/rasta-mouse/Watson)[0m
|
||
[*] OS Version: 1809 (17763)
|
||
[*] Enumerating installed KBs...
|
||
[1;31m [!] CVE-2019-0836 : VULNERABLE[0m
|
||
[1;31m [>] https://exploit-db.com/exploits/46718[0m
|
||
[1;31m [>] https://decoder.cloud/2019/04/29/combinig-luafv-postluafvpostreadwrite-race-condition-pe-with-diaghub-collector-exploit-from-standard-user-to-system/[0m
|
||
|
||
[1;31m [!] CVE-2019-0841 : VULNERABLE[0m
|
||
[1;31m [>] https://github.com/rogue-kdc/CVE-2019-0841[0m
|
||
[1;31m [>] https://rastamouse.me/tags/cve-2019-0841/[0m
|
||
|
||
[1;31m [!] CVE-2019-1064 : VULNERABLE[0m
|
||
[1;31m [>] https://www.rythmstick.net/posts/cve-2019-1064/[0m
|
||
|
||
[1;31m [!] CVE-2019-1130 : VULNERABLE[0m
|
||
[1;31m [>] https://github.com/S3cur3Th1sSh1t/SharpByeBear[0m
|
||
|
||
[1;31m [!] CVE-2019-1253 : VULNERABLE[0m
|
||
[1;31m [>] https://github.com/padovah4ck/CVE-2019-1253[0m
|
||
[1;31m [>] https://github.com/sgabe/CVE-2019-1253[0m
|
||
|
||
[1;31m [!] CVE-2019-1315 : VULNERABLE[0m
|
||
[1;31m [>] https://offsec.almond.consulting/windows-error-reporting-arbitrary-file-move-eop.html[0m
|
||
|
||
[1;31m [!] CVE-2019-1385 : VULNERABLE[0m
|
||
[1;31m [>] https://www.youtube.com/watch?v=K6gHnr-VkAg[0m
|
||
|
||
[1;31m [!] CVE-2019-1388 : VULNERABLE[0m
|
||
[1;31m [>] https://github.com/jas502n/CVE-2019-1388[0m
|
||
|
||
[1;31m [!] CVE-2019-1405 : VULNERABLE[0m
|
||
[1;31m [>] https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2019/november/cve-2019-1405-and-cve-2019-1322-elevation-to-system-via-the-upnp-device-host-service-and-the-update-orchestrator-service/[0m
|
||
[1;31m [>] https://github.com/apt69/COMahawk[0m
|
||
|
||
[1;31m [!] CVE-2020-0668 : VULNERABLE[0m
|
||
[1;31m [>] https://github.com/itm4n/SysTracingPoc[0m
|
||
|
||
[1;31m [!] CVE-2020-0683 : VULNERABLE[0m
|
||
[1;31m [>] https://github.com/padovah4ck/CVE-2020-0683[0m
|
||
[1;31m [>] https://raw.githubusercontent.com/S3cur3Th1sSh1t/Creds/master/PowershellScripts/cve-2020-0683.ps1[0m
|
||
|
||
[1;31m [!] CVE-2020-1013 : VULNERABLE[0m
|
||
[1;31m [>] https://www.gosecure.net/blog/2020/09/08/wsus-attacks-part-2-cve-2020-1013-a-windows-10-local-privilege-escalation-1-day/[0m
|
||
|
||
[1;31m [*] Finished. Found 12 potential vulnerabilities.
|
||
[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mShowing All Microsoft Updates[0m
|
||
[1;90m [X] Exception: Exception has been thrown by the target of an invocation.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSystem Last Shutdown Date/time (from Registry)
|
||
[0m
|
||
Last Shutdown Date/time : 10/31/2022 8:14:21 PM
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mUser Environment Variables[0m
|
||
[1;36m<36> [1;34mCheck for some passwords or keys in the env variables [1;33m[0m
|
||
[1;37m COMPUTER[0m[1;31mNAME[0m: [0mG0
|
||
[1;37m PUBLIC: [0mC:\Users\Public
|
||
[1;37m PSModulePath: [0m%ProgramFiles%\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
|
||
[1;37m PROCESSOR_ARCHITECTURE: [0mAMD64
|
||
[1;37m Path: [0mC:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\
|
||
[1;37m CommonProgramFiles(x86): [0mC:\Program Files (x86)\Common Files
|
||
[1;37m ProgramFiles(x86): [0mC:\Program Files (x86)
|
||
[1;37m PROCESSOR_LEVEL: [0m23
|
||
[1;37m ProgramFiles: [0mC:\Program Files
|
||
[1;37m PATHEXT: [0m.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
|
||
[1;37m USERPROFILE: [0mC:\Users\Default
|
||
[1;37m SystemRoot: [0mC:\Windows
|
||
[1;37m ALLUSERSPROFILE: [0mC:\ProgramData
|
||
[1;37m DriverData: [0mC:\Windows\System32\Drivers\DriverData
|
||
[1;37m ProgramData: [0mC:\ProgramData
|
||
[1;37m PROCESSOR_REVISION: [0m3100
|
||
[1;37m USER[0m[1;31mNAME[0m: [0mDefaultAppPool
|
||
[1;37m CommonProgramW6432: [0mC:\Program Files\Common Files
|
||
[1;37m CommonProgramFiles: [0mC:\Program Files\Common Files
|
||
[1;37m OS: [0mWindows_NT
|
||
[1;37m PROCESSOR_IDENTIFIER: [0mAMD64 Family 23 Model 49 Stepping 0, AuthenticAMD
|
||
[1;37m ComSpec: [0mC:\Windows\system32\cmd.exe
|
||
[1;37m PROMPT: [0m$P$G
|
||
[1;37m SystemDrive: [0mC:
|
||
[1;37m TEMP: [0mC:\Windows\TEMP
|
||
[1;37m NUMBER_OF_PROCESSORS: [0m2
|
||
[1;37m TMP: [0mC:\Windows\TEMP
|
||
[1;37m ProgramW6432: [0mC:\Program Files
|
||
[1;37m windir: [0mC:\Windows
|
||
[1;37m USERDOMAIN: [0mIIS APPPOOL
|
||
[1;37m USERDNSDOMAIN: [0mflight.htb
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSystem Environment Variables[0m
|
||
[1;36m<36> [1;34mCheck for some passwords or keys in the env variables [1;33m[0m
|
||
[1;37m ComSpec: [0mC:\Windows\system32\cmd.exe
|
||
[1;37m DriverData: [0mC:\Windows\System32\Drivers\DriverData
|
||
[1;37m OS: [0mWindows_NT
|
||
[1;37m Path: [0mC:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\
|
||
[1;37m PATHEXT: [0m.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
|
||
[1;37m PROCESSOR_ARCHITECTURE: [0mAMD64
|
||
[1;37m PSModulePath: [0mC:\Program Files\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules
|
||
[1;37m TEMP: [0mC:\Windows\TEMP
|
||
[1;37m TMP: [0mC:\Windows\TEMP
|
||
[1;37m USER[0m[1;31mNAME[0m: [0mSYSTEM
|
||
[1;37m windir: [0mC:\Windows
|
||
[1;37m NUMBER_OF_PROCESSORS: [0m2
|
||
[1;37m PROCESSOR_LEVEL: [0m23
|
||
[1;37m PROCESSOR_IDENTIFIER: [0mAMD64 Family 23 Model 49 Stepping 0, AuthenticAMD
|
||
[1;37m PROCESSOR_REVISION: [0m3100
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mAudit Settings[0m
|
||
[1;36m<36> [1;34mCheck what is being logged [1;33m[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mAudit Policy Settings - Classic & Advanced[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mWEF Settings[0m
|
||
[1;36m<36> [1;34mWindows Event Forwarding, is interesting to know were are sent the logs [1;33m[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLAPS Settings[0m
|
||
[1;36m<36> [1;34mIf installed, local administrator password is changed frequently and is restricted by ACL [1;33m[0m
|
||
[1;37m LAPS Enabled: [0m[0m[1;31mLAPS not installed[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mWdigest[0m
|
||
[1;36m<36> [1;34mIf enabled, plain-text crds could be stored in LSASS [1;33mhttps://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-protections#wdigest[0m
|
||
[1;32m Wdigest is not enabled[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLSA Protection[0m
|
||
[1;36m<36> [1;34mIf enabled, a driver is needed to read LSASS memory (If Secure Boot or UEFI, RunAsPPL cannot be disabled by deleting the registry key) [1;33mhttps://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-protections#lsa-protection[0m
|
||
[1;31m LSA Protection is not enabled[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCredentials Guard[0m
|
||
[1;36m<36> [1;34mIf enabled, a driver is needed to read LSASS memory [1;33mhttps://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-protections#credential-guard[0m
|
||
[1;31m CredentialGuard is not enabled[0m
|
||
Virtualization Based Security Status: [0m[1;31mNot enabled[0m
|
||
Configured: [0m[1;31mFalse[0m
|
||
Running: [0m[1;31mFalse[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCached Creds[0m
|
||
[1;36m<36> [1;34mIf > 0, credentials will be cached in the registry and accessible by SYSTEM user [1;33mhttps://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-protections#cached-credentials[0m
|
||
[1;31m cachedlogonscount is 10[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating saved credentials in Registry (CurrentPass)[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mAV Information[0m
|
||
[1;90m [X] Exception: Invalid namespace [0m
|
||
[1;31m No AV was detected!![0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mWindows Defender configuration[0m
|
||
[1;34m Local Settings[0m
|
||
[1;34m Group Policy Settings[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mUAC Status[0m
|
||
[1;36m<36> [1;34mIf you are in the Administrators group check how to bypass the UAC [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#basic-uac-bypass-full-file-system-access[0m
|
||
[1;37m ConsentPromptBehaviorAdmin: [0m5 - [0m[1;31mPromptForNonWindowsBinaries[0m
|
||
[1;37m EnableLUA: [0m1
|
||
[1;37m LocalAccountTokenFilterPolicy: [0m
|
||
[1;37m FilterAdministratorToken: [0m
|
||
[1;32m [*] LocalAccountTokenFilterPolicy set to 0 and FilterAdministratorToken != 1.
|
||
[-] Only the RID-500 local admin account can be used for lateral movement.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPowerShell Settings[0m
|
||
[1;37m PowerShell v2 Version: [0m2.0
|
||
[1;37m PowerShell v5 Version: [0m5.1.17763.1
|
||
[1;37m PowerShell Core Version: [0m
|
||
[1;37m Transcription Settings: [0m
|
||
[1;37m Module Logging Settings: [0m
|
||
[1;37m Scriptblock Logging Settings: [0m
|
||
[1;37m [0m[1;31mPS history file: [0m[0m
|
||
[1;37m [0m[1;31mPS history size: [0m[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating PowerShell Session Settings using the registry[0m
|
||
You must be an administrator to run this check
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPS default transcripts history[0m
|
||
[1;36m<36> [1;34mRead the PS history inside these files (if any)[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mHKCU Internet Settings[0m
|
||
[1;37m User Agent: [0mMozilla/4.0 (compatible; MSIE 8.0; Win32)
|
||
[1;37m IE5_UA_Backup_Flag: [0m5.0
|
||
[1;37m ZonesSecurityUpgrade: [0mSystem.Byte[]
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mHKLM Internet Settings[0m
|
||
[1;37m ActiveXCache: [0mC:\Windows\Downloaded Program Files
|
||
[1;37m CodeBaseSearchPath: [0mCODEBASE
|
||
[1;37m EnablePunycode: [0m1
|
||
[1;37m MinorVersion: [0m0
|
||
[1;37m WarnOnIntranet: [0m1
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mDrives Information[0m
|
||
[1;36m<36> [1;34mRemember that you should search more info inside the other drives [1;33m[0m
|
||
C:\ (Type: Fixed)(Filesystem: NTFS)(Available space: 4 GB)([0m[1;31mPermissions: Users [AppendData/CreateDirectories])[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking WSUS[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#wsus[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking KrbRelayUp[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#krbrelayup[0m
|
||
[1;31m The system is inside a domain (IIS APPPOOL) so it could be vulnerable.[0m
|
||
[1;36m<36> [1;34mYou can try https://github.com/Dec0ne/KrbRelayUp to escalate privileges[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking If Inside Container[0m
|
||
[1;36m<36> [1;34mIf the binary cexecsvc.exe or associated service exists, you are inside Docker [1;33m[0m
|
||
[1;32mYou are NOT inside a container[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking AlwaysInstallElevated[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#alwaysinstallelevated[0m
|
||
[1;32m AlwaysInstallElevated isn't available[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerate LSA settings - auth packages included
|
||
[0m
|
||
auditbasedirectories : 0
|
||
auditbaseobjects : 0
|
||
Bounds : 00-30-00-00-00-20-00-00
|
||
crashonauditfail : 0
|
||
fullprivilegeauditing : 00
|
||
LimitBlankPasswordUse : 1
|
||
NoLmHash : 1
|
||
Security Packages : ""
|
||
Notification Packages : rassfm,scecli
|
||
Authentication Packages : msv1_0
|
||
LsaPid : 656
|
||
LsaCfgFlagsDefault : 0
|
||
SecureBoot : 1
|
||
ProductType : 7
|
||
disabledomaincreds : 0
|
||
everyoneincludesanonymous : 0
|
||
forceguest : 0
|
||
restrictanonymous : 0
|
||
restrictanonymoussam : 1
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating NTLM Settings[0m
|
||
[1;31m LanmanCompatibilityLevel : (Send NTLMv2 response only - Win7+ default)
|
||
[0m
|
||
[1;34m
|
||
NTLM Signing Settings[0m
|
||
ClientRequireSigning : [0m[1;31mFalse[0m
|
||
ClientNegotiateSigning : [0m[1;32mTrue[0m
|
||
ServerRequireSigning : [0m[1;32mTrue[0m
|
||
ServerNegotiateSigning : [0m[1;32mTrue[0m
|
||
LdapSigning : [0m[33m[0m[33mNegotiate signing[0m[0m ([0m[33m[0m[33mNegotiate signing[0m[0m)
|
||
[1;34m
|
||
Session Security[0m
|
||
[1;32m NTLMMinClientSec : 536870912 (Require 128-bit encryption)[0m
|
||
[1;32m NTLMMinServerSec : 536870912 (Require 128-bit encryption)
|
||
[0m
|
||
[1;34m
|
||
NTLM Auditing and Restrictions[0m
|
||
InboundRestrictions : (Not defined)
|
||
[1;31m OutboundRestrictions : (Not defined)[0m
|
||
InboundAuditing : (Not defined)
|
||
OutboundExceptions :
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mDisplay Local Group Policy settings - local users/machine[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking AppLocker effective policy[0m
|
||
AppLockerPolicy version: 1
|
||
listing rules:
|
||
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Printers (WMI)[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Named Pipes[0m
|
||
Name CurrentUserPerms Sddl
|
||
|
||
CPFATP_948_v4.0.30319 [0m[1;31mDefaultAppPool [WriteData/CreateFiles][0m O:S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415G:S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415D:P(A;;0x12019f;;;BA)(A;;0x12019f;;;S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415)
|
||
|
||
eventlog [0m[1;31mEveryone [WriteData/CreateFiles][0m O:LSG:LSD:P(A;;0x12019b;;;WD)(A;;CC;;;OW)(A;;0x12008f;;;S-1-5-80-880578595-1860270145-482643319-2788375705-1540778122)
|
||
|
||
iislogpipe77b3ad5f-db2f-4ceb-9dc3-521a4a754b6f [0m[1;31mDefaultAppPool [AllAccess][0m O:S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415G:S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415D:P(A;;FA;;;SY)(A;;FA;;;S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415)
|
||
|
||
ROUTER [0m[1;31mEveryone [WriteData/CreateFiles][0m O:SYG:SYD:P(A;;0x12019b;;;WD)(A;;0x12019b;;;AN)(A;;FA;;;SY)
|
||
|
||
RpcProxy\49673 [0m[1;31mEveryone [WriteData/CreateFiles][0m O:BAG:SYD:(A;;0x12019b;;;WD)(A;;0x12019b;;;AN)(A;;FA;;;BA)
|
||
|
||
RpcProxy\593 [0m[1;31mEveryone [WriteData/CreateFiles][0m O:NSG:NSD:(A;;0x12019b;;;WD)(A;;RC;;;OW)(A;;0x12019b;;;AN)(A;;FA;;;S-1-5-80-521322694-906040134-3864710659-1525148216-3451224162)(A;;FA;;;S-1-5-80-979556362-403687129-3954533659-2335141334-1547273080)
|
||
|
||
vgauth-service [0m[1;31mEveryone [WriteData/CreateFiles][0m O:BAG:SYD:P(A;;0x12019f;;;WD)(A;;FA;;;SY)(A;;FA;;;BA)
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating AMSI registered providers[0m
|
||
Provider: {2781761E-28E0-4109-99FE-B9D127C57AFE}
|
||
Path: "C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2209.7-0\MpOav.dll"
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Sysmon configuration[0m
|
||
You must be an administrator to run this check
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Sysmon process creation logs (1)[0m
|
||
You must be an administrator to run this check
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mInstalled .NET versions
|
||
[0m
|
||
[1;34m CLR Versions[0m
|
||
4.0.30319
|
||
[1;34m
|
||
.NET Versions[0m
|
||
4.7.03190
|
||
[1;34m
|
||
.NET & AMSI (Anti-Malware Scan Interface) support[0m
|
||
.NET version supports AMSI : [0m[1;31mFalse[0m
|
||
OS supports AMSI : [0m[1;32mTrue[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mInteresting Events information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPrinting Explicit Credential Events (4648) for last 30 days - A process logged on using plaintext credentials
|
||
[0m
|
||
You must be an administrator to run this check
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPrinting Account Logon Events (4624) for the last 10 days.
|
||
[0m
|
||
You must be an administrator to run this check
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mProcess creation events - searching logs (EID 4688) for sensitive data.
|
||
[0m
|
||
You must be an administrator to run this check
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPowerShell events - script block logs (EID 4104) - searching for sensitive data.
|
||
[0m
|
||
[1;90m [X] Exception: Attempted to perform an unauthorized operation.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mDisplaying Power off/on events for last 5 days
|
||
[0m
|
||
2/9/2023 5:49:08 AM : Startup
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mUsers Information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mUsers[0m
|
||
[1;36m<36> [1;34mCheck if you have some admin equivalent privileges [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#users-and-groups[0m
|
||
Current user: [0m[1;35mDefaultAppPool[0m
|
||
Current groups: Everyone, Builtin\Pre-Windows 2000 Compatible Access, Users, Service, Console Logon, Authenticated Users, This Organization, IIS_IUSRS, Local, S-1-5-82-0
|
||
[1;90m =================================================================================================[0m
|
||
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCurrent User Idle Time[0m
|
||
Current User : IIS APPPOOL\DefaultAppPool
|
||
Idle Time : 04h:36m:45s:218ms
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mDisplay Tenant information (DsRegCmd.exe /status)[0m
|
||
Tenant is NOT Azure AD Joined.
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCurrent Token privileges[0m
|
||
[1;36m<36> [1;34mCheck if you can escalate privilege using some enabled token [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#token-manipulation[0m
|
||
[1;37m SeAssignPrimaryTokenPrivilege: [0mDISABLED
|
||
[1;37m SeIncreaseQuotaPrivilege: [0mDISABLED
|
||
[1;37m SeMachineAccountPrivilege: [0mDISABLED
|
||
[1;37m SeAuditPrivilege: [0mDISABLED
|
||
[1;37m SeChangeNotifyPrivilege: [0mSE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
|
||
[1;37m SeImpersonatePrivilege: [0mSE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
|
||
[1;37m SeCreateGlobalPrivilege: [0mSE_PRIVILEGE_ENABLED_BY_DEFAULT, SE_PRIVILEGE_ENABLED
|
||
[1;37m SeIncreaseWorkingSetPrivilege: [0mDISABLED
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mClipboard text[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLogged users[0m
|
||
flight\svc_apache
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mDisplay information about local users[0m
|
||
Computer Name : G0
|
||
User Name : [0m[1;31mAdministrator[0m
|
||
User Id : 500
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : [0m[1;31mAdministrator[0m
|
||
Comment : Built-in account for administering the computer/domain
|
||
Last Logon : 2/9/2023 5:50:28 AM
|
||
Logons Count : 55
|
||
Password Last Set : 9/22/2022 12:17:02 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : [0m[33mGuest[0m
|
||
User Id : 501
|
||
Is Enabled : [0m[1;32mFalse[0m
|
||
User Type : [0m[33mGuest[0m
|
||
Comment : Built-in account for guest access to the computer/domain
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 1/1/1970 12:00:00 AM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : krbtgt
|
||
User Id : 502
|
||
Is Enabled : [0m[1;32mFalse[0m
|
||
User Type : User
|
||
Comment : Key Distribution Center Service Account
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 11:48:01 AM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : S.Moon
|
||
User Id : 1602
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Junion Web Developer
|
||
Last Logon : 2/9/2023 6:32:37 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : R.Cold
|
||
User Id : 1603
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : HR Assistant
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : G.Lors
|
||
User Id : 1604
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Sales manager
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : L.Kein
|
||
User Id : 1605
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Penetration tester
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : M.Gold
|
||
User Id : 1606
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Sysadmin
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : C.Bum
|
||
User Id : 1607
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Senior Web Developer
|
||
Last Logon : 2/9/2023 9:41:19 AM
|
||
Logons Count : 18
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : W.Walker
|
||
User Id : 1608
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Payroll officer
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : I.Francis
|
||
User Id : 1609
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Nobody knows why he's here
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : D.Truff
|
||
User Id : 1610
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Project Manager
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : V.Stevens
|
||
User Id : 1611
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Secretary
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:22 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : svc_apache
|
||
User Id : 1612
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Service Apache web
|
||
Last Logon : 2/9/2023 5:49:59 AM
|
||
Logons Count : 26
|
||
Password Last Set : 9/22/2022 12:08:23 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
Computer Name : G0
|
||
User Name : O.Possum
|
||
User Id : 1613
|
||
Is Enabled : [0m[1;31mTrue[0m
|
||
User Type : User
|
||
Comment : Helpdesk
|
||
Last Logon : 1/1/1970 12:00:00 AM
|
||
Logons Count : 0
|
||
Password Last Set : 9/22/2022 12:08:23 PM
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mRDP Sessions[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEver logged users[0m
|
||
[0m[1;35mIIS APPPOOL[0m\.NET v4.5 Classic
|
||
[0m[1;35mIIS APPPOOL[0m\.NET v4.5
|
||
flight\Administrator
|
||
flight\svc_apache
|
||
flight\C.Bum
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mHome folders found[0m
|
||
[1;32m C:\Users\.NET v4.5[0m
|
||
[1;32m C:\Users\.NET v4.5 Classic[0m
|
||
[1;32m C:\Users\Administrator[0m
|
||
[1;32m C:\Users\All Users[0m
|
||
[1;32m C:\Users\C.Bum[0m
|
||
[1;32m C:\Users\Default[0m
|
||
[1;32m C:\Users\Default User[0m
|
||
[1;31m C:\Users\Public : Service [WriteData/CreateFiles][0m
|
||
[1;32m C:\Users\svc_apache[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for AutoLogon credentials[0m
|
||
[1;31m Some AutoLogon credentials were found[0m
|
||
DefaultDomainName : flight
|
||
DefaultUserName : Administrator
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPassword Policies[0m
|
||
[1;36m<36> [1;34mCheck for a possible brute-force [1;33m[0m
|
||
[1;37m Domain: [0mBuiltin
|
||
[1;37m SID: [0mS-1-5-32
|
||
[1;37m MaxPasswordAge: [0m42.22:47:31.7437440
|
||
[1;37m MinPasswordAge: [0m00:00:00
|
||
[1;37m MinPasswordLength: [0m0
|
||
[1;37m PasswordHistoryLength: [0m0
|
||
[1;37m PasswordProperties: [0m0
|
||
[1;90m =================================================================================================[0m
|
||
|
||
[1;37m Domain: [0mflight
|
||
[1;37m SID: [0mS-1-5-21-4078382237-1492182817-2568127209
|
||
[1;37m MaxPasswordAge: [0m42.00:00:00
|
||
[1;37m MinPasswordAge: [0m1.00:00:00
|
||
[1;37m MinPasswordLength: [0m7
|
||
[1;37m PasswordHistoryLength: [0m24
|
||
[1;37m PasswordProperties: [0mDOMAIN_PASSWORD_COMPLEX
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPrint Logon Sessions[0m
|
||
Method: WMI
|
||
Logon Server:
|
||
Logon Server Dns Domain:
|
||
Logon Id: 35046227
|
||
Logon Time:
|
||
Logon Type: Service
|
||
Start Time: 2/9/2023 10:04:51 AM
|
||
Domain: IIS APPPOOL
|
||
Authentication Package: Negotiate
|
||
Start Time: 2/9/2023 10:04:51 AM
|
||
User Name: DefaultAppPool
|
||
User Principal Name:
|
||
User SID:
|
||
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mProcesses Information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mVulnerable Leaked Handlers[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/leaked-handle-exploitation[0m
|
||
[1;37m Handle: [0m2556(key)
|
||
[1;37m Handle Owner: [0mPid is 4552(winPEASx64_ofs) with owner: [0m[1;31mDefaultAppPool[0m
|
||
[1;37m Reason: [0m[0m[1;31mAllAccess[0m
|
||
[1;37m Registry: [0mHKU\.default\software\classes
|
||
[1;90m =================================================================================================[0m
|
||
|
||
[1;37m Handle: [0m2636(key)
|
||
[1;37m Handle Owner: [0mPid is 4552(winPEASx64_ofs) with owner: [0m[1;31mDefaultAppPool[0m
|
||
[1;37m Reason: [0mTakeOwnership
|
||
[1;37m Registry: [0mHKLM\software\classes
|
||
[1;90m =================================================================================================[0m
|
||
|
||
[1;37m Handle: [0m2556(key)
|
||
[1;37m Handle Owner: [0mPid is 4552(winPEASx64_ofs) with owner: [0m[1;31mDefaultAppPool[0m
|
||
[1;37m Reason: [0mAllAccess
|
||
[1;37m Registry: [0mHKU\.default\software\classes
|
||
[1;90m =================================================================================================[0m
|
||
|
||
[1;37m Handle: [0m2636(key)
|
||
[1;37m Handle Owner: [0mPid is 4552(winPEASx64_ofs) with owner: [0m[1;31mDefaultAppPool[0m
|
||
[1;37m Reason: [0m[0m[1;31mTakeOwnership[0m
|
||
[1;37m Registry: [0mHKLM\software\classes
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mServices Information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mInteresting Services -non Microsoft-[0m
|
||
[1;36m<36> [1;34mCheck if you can overwrite some service binary or perform a DLL hijacking, also check for unquoted paths [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#services[0m
|
||
ApacheHTTPServer(Apache Software Foundation - Apache HTTP Server)[[0m[1;31m"C:\Xampp\apache\bin\httpd.exe" -k runservice[0m] - Auto - Running
|
||
[0m[1;31mPossible DLL Hijacking in binary folder: C:\Xampp\apache\bin (Users [AppendData/CreateDirectories WriteData/CreateFiles])[0m
|
||
[1;37mApache/2.4.52 (Win64)
|
||
[1;90m =================================================================================================[0m
|
||
|
||
ssh-agent(OpenSSH Authentication Agent)[[0m[1;32mC:\Windows\System32\OpenSSH\ssh-agent.exe[0m] - Disabled - Stopped
|
||
[1;37mAgent to hold private keys used for public key authentication.
|
||
[1;90m =================================================================================================[0m
|
||
|
||
VGAuthService(VMware, Inc. - VMware Alias Manager and Ticket Service)[[0m[1;32m"C:\Program Files\VMware\VMware Tools\VMware VGAuth\VGAuthService.exe"[0m] - Auto - Running
|
||
[1;37mAlias Manager and Ticket Service
|
||
[1;90m =================================================================================================[0m
|
||
|
||
vm3dservice(VMware, Inc. - VMware SVGA Helper Service)[[0m[1;32mC:\Windows\system32\vm3dservice.exe[0m] - Auto - Running
|
||
[1;37mHelps VMware SVGA driver by collecting and conveying user mode information
|
||
[1;90m =================================================================================================[0m
|
||
|
||
VMTools(VMware, Inc. - VMware Tools)[[0m[1;32m"C:\Program Files\VMware\VMware Tools\vmtoolsd.exe"[0m] - Auto - Running
|
||
[1;37mProvides support for synchronizing objects between the host and guest operating systems.
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mModifiable Services[0m
|
||
[1;36m<36> [1;34mCheck if you can modify any service [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#services[0m
|
||
[1;31m LOOKS LIKE YOU CAN MODIFY OR START/STOP SOME SERVICE/s:[0m
|
||
RmSvc: GenericExecute ([0m[33mStart[0m/[0m[33mStop[0m)
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking if you can modify any service registry[0m
|
||
[1;36m<36> [1;34mCheck if you can modify the registry of a service [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#services-registry-permissions[0m
|
||
[1;32m [-] Looks like you cannot change the registry of any service...[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking write permissions in PATH folders (DLL Hijacking)[0m
|
||
[1;36m<36> [1;34mCheck for DLL Hijacking in PATH folders [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#dll-hijacking[0m
|
||
[1;32m C:\Windows\system32[0m
|
||
[1;32m C:\Windows[0m
|
||
[1;32m C:\Windows\System32\Wbem[0m
|
||
[1;32m C:\Windows\System32\WindowsPowerShell\v1.0\[0m
|
||
[1;32m C:\Windows\System32\OpenSSH\[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mApplications Information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCurrent Active Window Application[0m
|
||
[1;90m [X] Exception: Object reference not set to an instance of an object.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mInstalled Applications --Via Program Files/Uninstall registry--[0m
|
||
[1;36m<36> [1;34mCheck if you can modify installed software [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#software[0m
|
||
[1;32m C:\Program Files\Common Files[0m
|
||
[1;32m C:\Program Files\desktop.ini[0m
|
||
[1;32m C:\Program Files\internet explorer[0m
|
||
[1;32m C:\Program Files\Uninstall Information[0m
|
||
[1;32m C:\Program Files\VMware[0m
|
||
[1;32m C:\Program Files\Windows Defender[0m
|
||
[1;32m C:\Program Files\Windows Defender Advanced Threat Protection[0m
|
||
[1;32m C:\Program Files\Windows Mail[0m
|
||
[1;32m C:\Program Files\Windows Media Player[0m
|
||
[1;32m C:\Program Files\Windows Multimedia Platform[0m
|
||
[1;32m C:\Program Files\windows nt[0m
|
||
[1;32m C:\Program Files\Windows Photo Viewer[0m
|
||
[1;32m C:\Program Files\Windows Portable Devices[0m
|
||
[1;32m C:\Program Files\Windows Security[0m
|
||
[1;32m C:\Program Files\Windows Sidebar[0m
|
||
[1;32m C:\Program Files\WindowsApps[0m
|
||
[1;32m C:\Program Files\WindowsPowerShell[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mAutorun Applications[0m
|
||
[1;36m<36> [1;34mCheck if you can modify other users AutoRuns binaries (Note that is normal that you can modify HKCU registry and binaries indicated there) [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries[0m
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows\CurrentVersion\Run[0m
|
||
Key: SecurityHealth
|
||
Folder: [0m[1;32mC:\Windows\system32[0m
|
||
File: [0m[1;32mC:\Windows\system32[0m\SecurityHealthSystray.exe
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows\CurrentVersion\Run[0m
|
||
Key: VMware User Process
|
||
Folder: [0m[1;32mC:\Program Files\VMware\VMware Tools[0m
|
||
File: [0m[1;32mC:\Program Files\VMware\VMware Tools[0m\vmtoolsd.exe -n vmusr ([0m[1;31mUnquoted and Space detected[0m)
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders[0m
|
||
Key: Common Startup
|
||
Folder: [0m[1;32mC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup[0m ([0m[1;31mUnquoted and Space detected[0m)
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders[0m
|
||
Key: Common Startup
|
||
Folder: [0m[1;32mC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup[0m ([0m[1;31mUnquoted and Space detected[0m)
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon[0m
|
||
Key: Userinit
|
||
Folder: [0m[1;32mC:\Windows\system32[0m
|
||
File: [0m[1;32mC:\Windows\system32[0m\userinit.exe,
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon[0m
|
||
Key: Shell
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mexplorer.exe[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\SYSTEM\CurrentControlSet\Control\SafeBoot[0m
|
||
Key: AlternateShell
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mcmd.exe[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Font Drivers[0m
|
||
Key: Adobe Type Manager
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32matmfd.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Font Drivers[0m
|
||
Key: Adobe Type Manager
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32matmfd.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: midimapper
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmidimap.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.imaadpcm
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mimaadp32.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.l3acm
|
||
Folder: [0m[1;32mC:\Windows\System32[0m
|
||
File: [0m[1;32mC:\Windows\System32[0m\l3codeca.acm
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.msadpcm
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsadp32.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.msg711
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsg711.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.msgsm610
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsgsm32.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.i420
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32miyuv_32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.iyuv
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32miyuv_32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.mrle
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsrle32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.msvc
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsvidc32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.uyvy
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.yuy2
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.yvu9
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mtsbyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.yvyu
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: wavemapper
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsacm32.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: wave
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: midi
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: mixer
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: aux
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: midimapper
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmidimap.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.imaadpcm
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mimaadp32.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.l3acm
|
||
Folder: [0m[1;32mC:\Windows\SysWOW64[0m
|
||
File: [0m[1;32mC:\Windows\SysWOW64[0m\l3codeca.acm
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.msadpcm
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsadp32.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.msg711
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsg711.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: msacm.msgsm610
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsgsm32.acm[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.cvid
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32miccvid.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.i420
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32miyuv_32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.iyuv
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32miyuv_32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.mrle
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsrle32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.msvc
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsvidc32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.uyvy
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.yuy2
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.yvu9
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mtsbyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: vidc.yvyu
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsyuv.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: wavemapper
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mmsacm32.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: wave
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: midi
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: mixer
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Drivers32[0m
|
||
Key: aux
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwdmaud.drv[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Classes\htmlfile\shell\open\command[0m
|
||
Folder: [0m[1;32mC:\Program Files\Internet Explorer[0m
|
||
File: [0m[1;32mC:\Program Files\Internet Explorer[0m\iexplore.exe %1 ([0m[1;31mUnquoted and Space detected[0m)
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: _wow64cpu
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwow64cpu.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: _wowarmhw
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwowarmhw.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: _xtajit
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mxtajit.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: advapi32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32madvapi32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: clbcatq
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mclbcatq.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: combase
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mcombase.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: COMDLG32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mCOMDLG32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: coml2
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mcoml2.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: DifxApi
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mdifxapi.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: gdi32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mgdi32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: gdiplus
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mgdiplus.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: IMAGEHLP
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mIMAGEHLP.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: IMM32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mIMM32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: kernel32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mkernel32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: MSCTF
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mMSCTF.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: MSVCRT
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mMSVCRT.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: NORMALIZ
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mNORMALIZ.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: NSI
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mNSI.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: ole32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mole32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: OLEAUT32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mOLEAUT32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: PSAPI
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mPSAPI.DLL[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: rpcrt4
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mrpcrt4.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: sechost
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32msechost.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: Setupapi
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mSetupapi.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: SHCORE
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mSHCORE.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: SHELL32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mSHELL32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: SHLWAPI
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mSHLWAPI.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: user32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32muser32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: WLDAP32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mWLDAP32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: wow64
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwow64.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: wow64win
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mwow64win.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls[0m
|
||
Key: WS2_32
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mWS2_32.dll[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: HKLM[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m\[0m[0m[0m[0m[0mSoftware[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m\[0m[0m[0m[0m[0mMicrosoft[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m\[0m[0m[0m[0m[0mActive Setup[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m\[0m[0m[0m[0m[0mInstalled Components[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m[0m[1;31m\[0m[0m[0m[0m[0m{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
|
||
Key: StubPath
|
||
Folder: [0m[1;31m\[0m
|
||
[0m[1;31mFolderPerms: Users [AppendData/CreateDirectories][0m
|
||
File: [0m[1;32m/UserInstall[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}[0m
|
||
Key: StubPath
|
||
Folder: [0m[1;32mC:\Windows\system32[0m
|
||
File: [0m[1;32mC:\Windows\system32[0m\unregmp2.exe /FirstLogon
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}[0m
|
||
Key: StubPath
|
||
Folder: None ([0m[1;31mPATH Injection[0m)
|
||
File: [0m[1;32mU[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}[0m
|
||
Key: StubPath
|
||
Folder: [0m[1;32mC:\Windows\System32[0m
|
||
File: [0m[1;32mC:\Windows\System32[0m\ie4uinit.exe -UserConfig
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}[0m
|
||
Key: StubPath
|
||
Folder: [0m[1;32mC:\Windows\System32[0m
|
||
File: [0m[1;32m[0m[1;32mC:\Windows\System32[0m[0m\Rundll32.exe [0m[1;32m[0m[1;32mC:\Windows\System32[0m[0m\mscories.dll,Install
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Active Setup\Installed Components\{A509B1A7-37EF-4b3f-8CFC-4F3A74704073}[0m
|
||
Key: StubPath
|
||
Folder: [0m[1;32mC:\Windows\System32[0m
|
||
File: [0m[1;32m[0m[1;32mC:\Windows\System32[0m[0m\rundll32.exe [0m[1;32m[0m[1;32mC:\Windows\System32[0m[0m\iesetup.dll,IEHardenAdmin
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Microsoft\Active Setup\Installed Components\{A509B1A8-37EF-4b3f-8CFC-4F3A74704073}[0m
|
||
Key: StubPath
|
||
Folder: [0m[1;32mC:\Windows\System32[0m
|
||
File: [0m[1;32m[0m[1;32mC:\Windows\System32[0m[0m\rundll32.exe [0m[1;32m[0m[1;32mC:\Windows\System32[0m[0m\iesetup.dll,IEHardenUser
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}[0m
|
||
Key: StubPath
|
||
Folder: [0m[1;32mC:\Windows\system32[0m
|
||
File: [0m[1;32mC:\Windows\system32[0m\unregmp2.exe /FirstLogon
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
RegPath: [0m[1;32mHKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}[0m
|
||
Key: StubPath
|
||
Folder: [0m[1;32mC:\Windows\SysWOW64[0m
|
||
File: [0m[1;32m[0m[1;32mC:\Windows\SysWOW64[0m[0m\Rundll32.exe [0m[1;32m[0m[1;32mC:\Windows\SysWOW64[0m[0m\mscories.dll,Install
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
Folder: [0m[1;32mC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup[0m
|
||
File: [0m[1;32mC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup[0m\desktop.ini ([0m[1;31mUnquoted and Space detected[0m)
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
Folder: [0m[1;31mC:\windows\tasks[0m
|
||
[0m[1;31mFolderPerms: Authenticated Users [WriteData/CreateFiles][0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
Folder: [0m[1;31mC:\windows\system32\tasks[0m
|
||
[0m[1;31mFolderPerms: Authenticated Users [WriteData/CreateFiles][0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
Folder: [0m[1;32mC:\windows[0m
|
||
File: [0m[1;32mC:\windows[0m\system.ini
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
Folder: [0m[1;32mC:\windows[0m
|
||
File: [0m[1;32mC:\windows[0m\win.ini
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
Key: From WMIC
|
||
Folder: [0m[1;32mC:\Windows\system32[0m
|
||
File: [0m[1;32mC:\Windows\system32[0m\SecurityHealthSystray.exe
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
Key: From WMIC
|
||
Folder: [0m[1;32mC:\Program Files\VMware\VMware Tools[0m
|
||
File: [0m[1;32mC:\Program Files\VMware\VMware Tools[0m\vmtoolsd.exe -n vmusr
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mScheduled Applications --Non Microsoft--[0m
|
||
[1;36m<36> [1;34mCheck if you can modify other users scheduled binaries [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mDevice Drivers --Non Microsoft--[0m
|
||
[1;36m<36> [1;34mCheck 3rd party drivers for known vulnerabilities/rootkits. [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#vulnerable-drivers[0m
|
||
QLogic Gigabit Ethernet - 7.12.31.105 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\bxvbda.sys[0m
|
||
QLogic 10 GigE - 7.13.65.105 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\evbda.sys[0m
|
||
QLogic FastLinQ Ethernet - 8.33.20.103 [Cavium, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\qevbda.sys[0m
|
||
NVIDIA nForce(TM) RAID Driver - 10.6.0.23 [NVIDIA Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\nvraid.sys[0m
|
||
VMware vSockets Service - 9.8.19.0 build-18956547 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\system32\DRIVERS\vsock.sys[0m
|
||
VMware PCI VMCI Bus Device - 9.8.18.0 build-18956547 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\vmci.sys[0m
|
||
Intel Matrix Storage Manager driver - 8.6.2.1019 [Intel Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\iaStorV.sys[0m
|
||
Promiser SuperTrak EX Series - 5.1.0000.10 [Promise Technology, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\stexstor.sys[0m
|
||
LSI 3ware RAID Controller - WindowsBlue [LSI]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\3ware.sys[0m
|
||
AHCI 1.3 Device Driver - 1.1.3.277 [Advanced Micro Devices]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\amdsata.sys[0m
|
||
Storage Filter Driver - 1.1.3.277 [Advanced Micro Devices]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\amdxata.sys[0m
|
||
AMD Technology AHCI Compatible Controller - 3.7.1540.43 [AMD Technologies Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\amdsbs.sys[0m
|
||
Adaptec RAID Controller - 7.5.0.32048 [PMC-Sierra, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\arcsas.sys[0m
|
||
Windows (R) Win 7 DDK driver - 10.0.10011.16384 [Avago Technologies]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\ItSas35i.sys[0m
|
||
LSI Fusion-MPT SAS Driver (StorPort) - 1.34.03.83 [LSI Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\lsi_sas.sys[0m
|
||
Windows (R) Win 7 DDK driver - 10.0.10011.16384 [LSI Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\lsi_sas2i.sys[0m
|
||
Windows (R) Win 7 DDK driver - 10.0.10011.16384 [Avago Technologies]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\lsi_sas3i.sys[0m
|
||
LSI SSS PCIe/Flash Driver (StorPort) - 2.10.61.81 [LSI Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\lsi_sss.sys[0m
|
||
MEGASAS RAID Controller Driver for Windows - 6.706.06.00 [Avago Technologies]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\megasas.sys[0m
|
||
MEGASAS RAID Controller Driver for Windows - 6.714.05.00 [Avago Technologies]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\MegaSas2i.sys[0m
|
||
MEGASAS RAID Controller Driver for Windows - 7.705.08.00 [Avago Technologies]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\megasas35i.sys[0m
|
||
MegaRAID Software RAID - 15.02.2013.0129 [LSI Corporation, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\megasr.sys[0m
|
||
Marvell Flash Controller - 1.0.5.1016 [Marvell Semiconductor, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\mvumis.sys[0m
|
||
NVIDIA nForce(TM) SATA Driver - 10.6.0.23 [NVIDIA Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\nvstor.sys[0m
|
||
MEGASAS RAID Controller Driver for Windows - 6.805.03.00 [Avago Technologies]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\percsas2i.sys[0m
|
||
MEGASAS RAID Controller Driver for Windows - 6.604.06.00 [Avago Technologies]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\percsas3i.sys[0m
|
||
Microsoftr Windowsr Operating System - 2.60.01 [Silicon Integrated Systems Corp.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\SiSRaid2.sys[0m
|
||
Microsoftr Windowsr Operating System - 6.1.6918.0 [Silicon Integrated Systems]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\sisraid4.sys[0m
|
||
VIA RAID driver - 7.0.9600,6352 [VIA Technologies Inc.,Ltd]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\vsmraid.sys[0m
|
||
VIA StorX RAID Controller Driver - 8.0.9200.8110 [VIA Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\vstxraid.sys[0m
|
||
Chelsio Communications iSCSI Controller - 10.0.10011.16384 [Chelsio Communications]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\cht4sx64.sys[0m
|
||
Intel(R) Rapid Storage Technology driver (inbox) - 15.44.0.1010 [Intel Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\iaStorAVC.sys[0m
|
||
QLogic BR-series FC/FCoE HBA Stor Miniport Driver - 3.2.26.1 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\bfadfcoei.sys[0m
|
||
Emulex WS2K12 Storport Miniport Driver x64 - 11.0.247.8000 01/26/2016 WS2K12 64 bit x64 [Emulex]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\elxfcoe.sys[0m
|
||
Emulex WS2K12 Storport Miniport Driver x64 - 11.4.225.8009 11/15/2017 WS2K12 64 bit x64 [Broadcom]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\elxstor.sys[0m
|
||
QLogic iSCSI offload driver - 8.33.5.2 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\qeois.sys[0m
|
||
QLogic Fibre Channel Stor Miniport Driver - 9.1.15.1 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\ql2300i.sys[0m
|
||
QLA40XX iSCSI Host Bus Adapter - 2.1.5.0 (STOREx wx64) [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\ql40xx2i.sys[0m
|
||
QLogic FCoE Stor Miniport Inbox Driver - 9.1.11.3 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\qlfcoei.sys[0m
|
||
PMC-Sierra HBA Controller - 1.3.0.10769 [PMC-Sierra]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\ADP80XX.SYS[0m
|
||
QLogic BR-series FC/FCoE HBA Stor Miniport Driver - 3.2.26.1 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\bfadi.sys[0m
|
||
Smart Array SAS/SATA Controller Media Driver - 8.0.4.0 Build 1 Media Driver (x86-64) [Hewlett-Packard Company]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\HpSAMD.sys[0m
|
||
SmartRAID, SmartHBA PQI Storport Driver - 1.50.0.0 [Microsemi Corportation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\SmartSAMD.sys[0m
|
||
QLogic FCoE offload driver - 8.33.4.2 [Cavium, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\qefcoe.sys[0m
|
||
QLogic iSCSI offload driver - 7.14.7.2 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\bxois.sys[0m
|
||
QLogic FCoE Offload driver - 7.14.15.2 [QLogic Corporation]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\bxfcoe.sys[0m
|
||
VMware Raw Disk Helper Driver - 1.1.7.0 build-18933738 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\system32\DRIVERS\vmrawdsk.sys[0m
|
||
VMware Pointing PS/2 Device Driver - 12.5.12.0 build-18967789 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\vmmouse.sys[0m
|
||
VMware SVGA 3D - 9.17.01.0002 - build-18913173 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\system32\DRIVERS\vm3dmp_loader.sys[0m
|
||
VMware SVGA 3D - 9.17.01.0002 - build-18913173 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\system32\DRIVERS\vm3dmp.sys[0m
|
||
VMware PCIe Ethernet Adapter NDIS 6.30 (64-bit) - 1.9.9.0 build-19932667 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\System32\drivers\vmxnet3.sys[0m
|
||
VMware server memory controller - 7.5.7.0 build-18933738 [VMware, Inc.]: [0m[1;32m\\.\GLOBALROOT\SystemRoot\system32\DRIVERS\vmmemctl.sys[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mNetwork Information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mNetwork Shares[0m
|
||
[0m[1;32mADMIN$[0m ([1;37mPath: C:\Windows[0m)
|
||
[0m[1;32mC$[0m ([1;37mPath: C:\[0m)
|
||
[0m[1;32mIPC$[0m ([1;37mPath: [0m)
|
||
NETLOGON ([1;37mPath: C:\Windows\SYSVOL\sysvol\flight.htb\SCRIPTS[0m)
|
||
Shared ([1;37mPath: C:\Shared[0m)
|
||
SYSVOL ([1;37mPath: C:\Windows\SYSVOL\sysvol[0m)
|
||
Users ([1;37mPath: C:\Users[0m)
|
||
Web ([1;37mPath: C:\xampp\htdocs[0m)
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerate Network Mapped Drives (WMI)[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mHost File[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mNetwork Ifaces and known hosts[0m
|
||
[1;36m<36> [1;34mThe masks are only for the IPv4 addresses [1;33m[0m
|
||
Ethernet0 2[00:50:56:B9:24:63]: 10.10.11.187, fe80::3418:57dd:cff4:b69a%6, dead:beef::3418:57dd:cff4:b69a, dead:beef::13d / 255.255.254.0
|
||
[1;37mGateways: [0m10.10.10.2, fe80::250:56ff:feb9:cdb8%6
|
||
[1;37mDNSs: [0m1.1.1.1
|
||
[1;37mKnown hosts:[0m
|
||
10.10.10.2 00-50-56-B9-CD-B8 Dynamic
|
||
10.10.10.255 00-00-00-00-00-00 Invalid
|
||
10.10.11.255 FF-FF-FF-FF-FF-FF Static
|
||
224.0.0.22 01-00-5E-00-00-16 Static
|
||
224.0.0.251 01-00-5E-00-00-FB Static
|
||
224.0.0.252 01-00-5E-00-00-FC Static
|
||
|
||
Loopback Pseudo-Interface 1[]: 127.0.0.1, ::1 / 255.0.0.0
|
||
[1;37mDNSs: [0mfec0:0:0:ffff::1%1, fec0:0:0:ffff::2%1, fec0:0:0:ffff::3%1
|
||
[1;37mKnown hosts:[0m
|
||
224.0.0.22 00-00-00-00-00-00 Static
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCurrent TCP Listening Ports[0m
|
||
[1;36m<36> [1;34mCheck for services restricted from the outside [1;33m[0m
|
||
[1;34m Enumerating IPv4 connections
|
||
[0m
|
||
Protocol Local Address Local Port Remote Address Remote Port State Process ID Process Name
|
||
|
||
TCP 0.0.0.0 80 0.0.0.0 0 Listening 4620 httpd
|
||
TCP 0.0.0.0 88 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 135 0.0.0.0 0 Listening 912 svchost
|
||
TCP 0.0.0.0 389 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 443 0.0.0.0 0 Listening 4620 httpd
|
||
TCP 0.0.0.0 445 0.0.0.0 0 Listening 4 System
|
||
TCP 0.0.0.0 464 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 593 0.0.0.0 0 Listening 912 svchost
|
||
TCP 0.0.0.0 636 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 3268 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 3269 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 5985 0.0.0.0 0 Listening 4 System
|
||
TCP 0.0.0.0 8000 0.0.0.0 0 Listening 4 System
|
||
TCP 0.0.0.0 9389 0.0.0.0 0 Listening 2788 Microsoft.ActiveDirectory.WebServices
|
||
TCP 0.0.0.0 47001 0.0.0.0 0 Listening 4 System
|
||
TCP 0.0.0.0 49664 0.0.0.0 0 Listening 500 wininit
|
||
TCP 0.0.0.0 49665 0.0.0.0 0 Listening 1108 svchost
|
||
TCP 0.0.0.0 49666 0.0.0.0 0 Listening 1500 svchost
|
||
TCP 0.0.0.0 49668 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 49673 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 49674 0.0.0.0 0 Listening 656 lsass
|
||
TCP 0.0.0.0 49682 0.0.0.0 0 Listening 636 services
|
||
TCP 0.0.0.0 49690 0.0.0.0 0 Listening 2940 dns
|
||
TCP 0.0.0.0 49699 0.0.0.0 0 Listening 2888 dfsrs
|
||
TCP 10.10.11.187 53 0.0.0.0 0 Listening 2940 dns
|
||
TCP 10.10.11.187 139 0.0.0.0 0 Listening 4 System
|
||
TCP 10.10.11.187 445 10.10.16.3 41514 Established 4 System
|
||
TCP 10.10.11.187 50493 10.10.16.3 4445 Established 4340 conhost
|
||
TCP 10.10.11.187 56208 10.10.16.3 4445 Established 4332 rtcp64
|
||
TCP 10.10.11.187 57135 10.10.16.3 4444 Established 4720 httpd
|
||
TCP 10.10.11.187 61410 10.10.16.3 4445 Established 1916 rtcp64
|
||
TCP 10.10.11.187 61822 10.10.16.3 9999 Established 3504 chisel
|
||
TCP 10.10.11.187 62930 10.10.16.3 4445 Established 5852 C:\xampp\rtcp64.exe
|
||
TCP 10.10.11.187 62953 10.10.16.13 9999 SYN Sent 2136 chisel
|
||
TCP [0m[1;31m127.0.0.1[0m 53 0.0.0.0 0 Listening 2940 dns
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62046 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62049 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62059 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62417 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62841 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62844 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62845 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62846 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62855 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62898 Established 4 System
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62046 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62049 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62059 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62417 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62841 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62844 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62845 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62846 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62855 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
TCP [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 62898 [0m[1;31m[0m[1;31m127.0.0.1[0m[0m 8000 Established 3504 chisel
|
||
[0m[0m
|
||
[1;34m Enumerating IPv6 connections
|
||
[0m
|
||
Protocol Local Address Local Port Remote Address Remote Port State Process ID Process Name
|
||
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 80 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 4620 httpd
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 88 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 135 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 912 svchost
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 389 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 443 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 4620 httpd
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 445 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 4 System
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 464 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 593 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 912 svchost
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 636 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 3268 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 3269 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 5985 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 4 System
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 8000 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 4 System
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 9389 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 2788 Microsoft.ActiveDirectory.WebServices
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 47001 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 4 System
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49664 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 500 wininit
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49665 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 1108 svchost
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49666 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 1500 svchost
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49668 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49673 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49674 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49682 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 636 services
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49690 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 2940 dns
|
||
TCP [0m[1;31m[0m[1;31m[::][0m[0m 49699 [0m[1;31m[0m[1;31m[::][0m[0m 0 Listening 2888 dfsrs
|
||
TCP [0m[1;31m[::1][0m 53 [0m[1;31m[::][0m 0 Listening 2940 dns
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 389 [0m[1;31m[0m[1;31m[::1][0m[0m 49678 Established 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 389 [0m[1;31m[0m[1;31m[::1][0m[0m 49679 Established 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 389 [0m[1;31m[0m[1;31m[::1][0m[0m 49688 Established 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 389 [0m[1;31m[0m[1;31m[::1][0m[0m 49694 Established 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 389 [0m[1;31m[0m[1;31m[::1][0m[0m 49697 Established 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 49668 [0m[1;31m[0m[1;31m[::1][0m[0m 49696 Established 656 lsass
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 49678 [0m[1;31m[0m[1;31m[::1][0m[0m 389 Established 2972 ismserv
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 49679 [0m[1;31m[0m[1;31m[::1][0m[0m 389 Established 2972 ismserv
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 49688 [0m[1;31m[0m[1;31m[::1][0m[0m 389 Established 2940 dns
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 49694 [0m[1;31m[0m[1;31m[::1][0m[0m 389 Established 2888 dfsrs
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 49696 [0m[1;31m[0m[1;31m[::1][0m[0m 49668 Established 2888 dfsrs
|
||
TCP [0m[1;31m[0m[1;31m[::1][0m[0m 49697 [0m[1;31m[0m[1;31m[::1][0m[0m 389 Established 2888 dfsrs
|
||
TCP [dead:beef::13d] 53 [0m[1;31m[::][0m 0 Listening 2940 dns
|
||
TCP [dead:beef::3418:57dd:cff4:b69a] 53 [0m[1;31m[::][0m 0 Listening 2940 dns
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 53 [0m[1;31m[::][0m 0 Listening 2940 dns
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 389 [fe80::3418:57dd:cff4:b69a%6] 49689 Established 656 lsass
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 49668 [fe80::3418:57dd:cff4:b69a%6] 49754 Established 656 lsass
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 49668 [fe80::3418:57dd:cff4:b69a%6] 49869 Established 656 lsass
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 49668 [fe80::3418:57dd:cff4:b69a%6] 62950 Established 656 lsass
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 49689 [fe80::3418:57dd:cff4:b69a%6] 389 Established 2940 dns
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 49754 [fe80::3418:57dd:cff4:b69a%6] 49668 Established 656 lsass
|
||
TCP [fe80::3418:57dd:cff4:b69a%6] 49869 [fe80::3418:57dd:cff4:b69a%6] 49668 Established 2476 dfssvc
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCurrent UDP Listening Ports[0m
|
||
[1;36m<36> [1;34mCheck for services restricted from the outside [1;33m[0m
|
||
[1;34m Enumerating IPv4 connections
|
||
[0m
|
||
Protocol Local Address Local Port Remote Address:Remote Port Process ID Process Name
|
||
|
||
UDP 0.0.0.0 123 *:* 716 svchost
|
||
UDP 0.0.0.0 389 *:* 656 lsass
|
||
UDP 0.0.0.0 5353 *:* 1120 svchost
|
||
UDP 0.0.0.0 5355 *:* 1120 svchost
|
||
UDP 0.0.0.0 54488 *:* 1120 svchost
|
||
UDP 10.10.11.187 88 *:* 656 lsass
|
||
UDP 10.10.11.187 137 *:* 4 System
|
||
UDP 10.10.11.187 138 *:* 4 System
|
||
UDP 10.10.11.187 464 *:* 656 lsass
|
||
UDP [0m[1;31m127.0.0.1[0m 49483 *:* 2972 ismserv
|
||
UDP [0m[1;31m127.0.0.1[0m 50347 *:* 1968 svchost
|
||
UDP [0m[1;31m127.0.0.1[0m 54489 *:* 3032 svchost
|
||
UDP [0m[1;31m127.0.0.1[0m 54491 *:* 3952 WmiPrvSE
|
||
UDP [0m[1;31m127.0.0.1[0m 54496 *:* 4552 C:\Windows\TEMP\winPEASx64_ofs.exe
|
||
UDP [0m[1;31m127.0.0.1[0m 56562 *:* 2476 dfssvc
|
||
UDP [0m[1;31m127.0.0.1[0m 57083 *:* 1240 svchost
|
||
UDP [0m[1;31m127.0.0.1[0m 60507 *:* 2888 dfsrs
|
||
UDP [0m[1;31m127.0.0.1[0m 60550 *:* 2788 Microsoft.ActiveDirectory.WebServices
|
||
UDP [0m[1;31m127.0.0.1[0m 61455 *:* 1368 svchost
|
||
[0m[0m
|
||
[1;34m Enumerating IPv6 connections
|
||
[0m
|
||
Protocol Local Address Local Port Remote Address:Remote Port Process ID Process Name
|
||
|
||
UDP [0m[1;31m[::][0m 123 *:* 716 svchost
|
||
UDP [0m[1;31m[::][0m 389 *:* 656 lsass
|
||
UDP [0m[1;31m[::][0m 5353 *:* 1120 svchost
|
||
UDP [0m[1;31m[::][0m 5355 *:* 1120 svchost
|
||
UDP [0m[1;31m[::][0m 54488 *:* 1120 svchost
|
||
UDP [dead:beef::13d] 88 *:* 656 lsass
|
||
UDP [dead:beef::13d] 464 *:* 656 lsass
|
||
UDP [dead:beef::3418:57dd:cff4:b69a] 88 *:* 656 lsass
|
||
UDP [dead:beef::3418:57dd:cff4:b69a] 464 *:* 656 lsass
|
||
UDP [fe80::3418:57dd:cff4:b69a%6] 88 *:* 656 lsass
|
||
UDP [fe80::3418:57dd:cff4:b69a%6] 464 *:* 656 lsass
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFirewall Rules[0m
|
||
[1;36m<36> [1;34mShowing only DENY rules (too many ALLOW rules always) [1;33m[0m
|
||
Current Profiles: DOMAIN
|
||
FirewallEnabled (Domain): [0m[1;32mTrue[0m
|
||
FirewallEnabled (Private): [0m[1;32mTrue[0m
|
||
FirewallEnabled (Public): [0m[1;32mTrue[0m
|
||
[1;90m DENY rules:[0m
|
||
[1;90m [X] Exception: Object reference not set to an instance of an object.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mDNS cached --limit 70--[0m
|
||
[1;90m Entry Name Data[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Internet settings, zone and proxy configuration[0m
|
||
[1;34m General Settings[0m
|
||
Hive Key Value
|
||
HKCU User Agent Mozilla/4.0 (compatible; MSIE 8.0; Win32)
|
||
HKCU IE5_UA_Backup_Flag 5.0
|
||
HKCU ZonesSecurityUpgrade System.Byte[]
|
||
HKLM ActiveXCache C:\Windows\Downloaded Program Files
|
||
HKLM CodeBaseSearchPath CODEBASE
|
||
HKLM EnablePunycode 1
|
||
HKLM MinorVersion 0
|
||
HKLM WarnOnIntranet 1
|
||
[1;34m
|
||
Zone Maps[0m
|
||
No URLs configured
|
||
[1;34m
|
||
Zone Auth Settings[0m
|
||
No Zone Auth Settings
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mWindows Credentials[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking Windows Vault[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#credentials-manager-windows-vault[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking Credential manager[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#credentials-manager-windows-vault[0m
|
||
[!] [0m[33mWarning:[0m if password contains non-printable characters, it will be printed as unicode base64 encoded string
|
||
|
||
|
||
[!] Unable to enumerate credentials automatically, error: 'Win32Exception: System.ComponentModel.Win32Exception (0x80004005): Element not found'
|
||
Please run:
|
||
[33mcmdkey /list[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSaved RDP connections[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mRemote Desktop Server/Client Settings[0m
|
||
[1;34m RDP Server Settings[0m
|
||
Network Level Authentication :
|
||
Block Clipboard Redirection :
|
||
Block COM Port Redirection :
|
||
Block Drive Redirection :
|
||
Block LPT Port Redirection :
|
||
Block PnP Device Redirection :
|
||
Block Printer Redirection :
|
||
Allow Smart Card Redirection :
|
||
[1;34m
|
||
RDP Client Settings[0m
|
||
Disable Password Saving : True
|
||
Restricted Remote Administration : False
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mRecently run commands[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking for DPAPI Master Keys[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#dpapi[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking for DPAPI Credential Files[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#dpapi[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChecking for RDCMan Settings Files[0m
|
||
[1;36m<36> [1;34mDump credentials from Remote Desktop Connection Manager [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#remote-desktop-credential-manager[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for Kerberos tickets[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/pentesting/pentesting-kerberos-88[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for saved Wifi credentials[0m
|
||
[1;90m [X] Exception: Unable to load DLL 'wlanapi.dll': The specified module could not be found. (Exception from HRESULT: 0x8007007E)[0m
|
||
Enumerating WLAN using wlanapi.dll failed, trying to enumerate using 'netsh'
|
||
No saved Wifi credentials found
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking AppCmd.exe[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#appcmd-exe[0m
|
||
[1;31m AppCmd.exe was found in C:\Windows\system32\inetsrv\appcmd.exe[0m
|
||
You must be an administrator to run this check
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking SSClient.exe[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#scclient-sccm[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating SSCM - System Center Configuration Manager settings[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Security Packages Credentials[0m
|
||
[1;31m Version: NetNTLMv2
|
||
Hash: G0$::flight:1122334455667788:481bcd7edecd7c1f05b28363684fde3e:0101000000000000167309f5b33cd901530b32c803237f6d0000000008003000300000000000000000000000003000002755a3568a8f9afb587704de2295ccd9a81d9f4a43144fa432f7cf9d1e2be3f10a00100000000000000000000000000000000000090000000000000000000000
|
||
[0m
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mBrowsers Information[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mShowing saved credentials for Firefox[0m
|
||
[33m Info: if no credentials were listed, you might need to close the browser and try again.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for Firefox DBs[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#browsers-history[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for GET credentials in Firefox history[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#browsers-history[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mShowing saved credentials for Chrome[0m
|
||
[33m Info: if no credentials were listed, you might need to close the browser and try again.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for Chrome DBs[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#browsers-history[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for GET credentials in Chrome history[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#browsers-history[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mChrome bookmarks[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mShowing saved credentials for Opera[0m
|
||
[33m Info: if no credentials were listed, you might need to close the browser and try again.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mShowing saved credentials for Brave Browser[0m
|
||
[33m Info: if no credentials were listed, you might need to close the browser and try again.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mShowing saved credentials for Internet Explorer (unsupported)[0m
|
||
[33m Info: if no credentials were listed, you might need to close the browser and try again.[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCurrent IE tabs[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#browsers-history[0m
|
||
[1;90m [X] Exception: System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.Runtime.InteropServices.COMException: The server process could not be started because the configured identity is incorrect. Check the username and password. (Exception from HRESULT: 0x8000401A)
|
||
--- End of inner exception stack trace ---
|
||
at System.RuntimeType.InvokeDispMethod(String name, BindingFlags invokeAttr, Object target, Object[] args, Boolean[] byrefModifiers, Int32 culture, String[] namedParameters)
|
||
at System.RuntimeType.InvokeMember(String name, BindingFlags bindingFlags, Binder binder, Object target, Object[] providedArgs, ParameterModifier[] modifiers, CultureInfo culture, String[] namedParams)
|
||
at fk.l()[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for GET credentials in IE history[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#browsers-history[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mIE favorites[0m
|
||
[1;90m Not Found[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mInteresting files and registry[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPutty Sessions[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mPutty SSH Host keys[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSSH keys in registry[0m
|
||
[1;36m<36> [1;34mIf you find anything here, follow the link to learn how to decrypt the SSH keys [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#ssh-keys-in-registry[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSuperPutty configuration files[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Office 365 endpoints synced by OneDrive.
|
||
[0m
|
||
SID: S-1-5-19
|
||
[1;90m =================================================================================================[0m
|
||
|
||
SID: S-1-5-20
|
||
[1;90m =================================================================================================[0m
|
||
|
||
SID: S-1-5-21-4078382237-1492182817-2568127209-1612
|
||
[1;90m =================================================================================================[0m
|
||
|
||
SID: S-1-5-18
|
||
[1;90m =================================================================================================[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCloud Credentials[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#credentials-inside-files[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mUnattend Files[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for common SAM & SYSTEM backups[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for McAfee Sitelist.xml Files[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mCached GPP Passwords[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for possible regs with creds[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#inside-the-registry[0m
|
||
[1;90m Not Found[0m
|
||
[1;90m Not Found[0m
|
||
[1;90m Not Found[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for possible password files in users homes[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#credentials-inside-files[0m
|
||
C:\Users\All Users\Microsoft\UEV\InboxTemplates\Roaming[0m[1;31mCredential[0mSettings.xml
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSearching for Oracle SQL Developer config files
|
||
[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSlack files & directories[0m
|
||
[33m note: check manually if something is found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for LOL Binaries and Scripts (can be slow)[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://lolbas-project.github.io/[0m
|
||
[33m [!] Check skipped, if you want to run it, please specify '-lolbas' argument[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating Outlook download files
|
||
[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mEnumerating machine and user certificate files
|
||
[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSearching known files that can contain creds in home[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#credentials-inside-files[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for documents --limit 100--[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mOffice Most Recent Files -- limit 50
|
||
[0m
|
||
[1;34m Last Access Date User Application Document[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mRecent files --limit 70--[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking inside the Recycle Bin for creds files[0m
|
||
[1;36m<36> [1;34m [1;33mhttps://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation#credentials-inside-files[0m
|
||
[1;90m Not Found[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSearching hidden files or folders in C:\Users home (can be slow)
|
||
[0m
|
||
[1;31m C:\Users\All Users\ntuser.pol[0m
|
||
[1;31m C:\Users\Default User[0m
|
||
[1;31m C:\Users\Default[0m
|
||
[1;31m C:\Users\All Users[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSearching interesting files in other users home directories (can be slow)
|
||
[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mSearching executable files in non-default folders with write (equivalent) permissions (can be slow)[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mLooking for Linux shells/distributions - wsl.exe, bash.exe[0m
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFile Analysis[1;36m <20><><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD>[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFound MySQL Files[0m
|
||
Folder: C:\xampp\licenses\strawberry\licenses\[0m[1;31mmysql[0m
|
||
Folder: C:\xampp\licenses\[0m[1;31mmysql[0m
|
||
Folder: C:\xampp\licenses\[0m[1;31mmysql[0m
|
||
Folder: C:\xampp\[0m[1;31mmysql[0m
|
||
Folder: C:\xampp\php\data\phpdocref\[0m[1;31mmysql[0m
|
||
Folder: C:\xampp\perl\vendor\lib\DBD\[0m[1;31mmysql[0m
|
||
Folder: C:\xampp\perl\vendor\lib\auto\DBD\[0m[1;31mmysql[0m
|
||
Folder: C:\xampp\[0m[1;31m[0m[1;31mmysql[0m[0m\data\[0m[1;31m[0m[1;31mmysql[0m[0m
|
||
Folder: C:\xampp\[0m[1;31m[0m[1;31mmysql[0m[0m\backup\[0m[1;31m[0m[1;31mmysql[0m[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFound Apache-Nginx Files[0m
|
||
File: C:\xampp\php\[0m[1;31mphp.ini[0m
|
||
; PHP's initialization file, generally called php.ini, is responsible for
|
||
|
||
; configuring many of the aspects of PHP's behavior.
|
||
|
||
; PHP attempts to find and load this configuration from a number of locations.
|
||
|
||
; 1. SAPI module specific location.
|
||
|
||
; 2. The PHPRC environment variable. (As of PHP 5.2.0)
|
||
|
||
; 3. A number of predefined registry keys on Windows (As of PHP 5.2.0)
|
||
|
||
; 6. The directory from the --with-config-file-path compile time option, or the
|
||
|
||
; See the PHP docs for more specific information.
|
||
|
||
; https://php.net/configuration.file
|
||
|
||
; beginning with a semicolon are silently ignored (as you probably guessed).
|
||
|
||
; Section headers (e.g. [Foo]) are also silently ignored, even though
|
||
|
||
; Directives following the section heading [PATH=/www/mysite] only
|
||
|
||
; following the section heading [HOST=www.example.com] only apply to
|
||
|
||
; special sections cannot be overridden by user-defined INI files or
|
||
|
||
; at runtime. Currently, [PATH=] and [HOST=] sections only work under
|
||
|
||
; https://php.net/ini.sections
|
||
|
||
; Directives are variables used to configure PHP or PHP extensions.
|
||
|
||
; There is no name validation. If PHP can't find an expected
|
||
|
||
; The value can be a string, a number, a PHP constant (e.g. E_ALL or M_PI), one
|
||
|
||
; of the INI constants ([0m[1;31mOn[0m, Off, True, False, Yes, No and None) or an expression
|
||
|
||
; Expressions in the INI file are limited to bitwise operators and parentheses:
|
||
|
||
; Boolean flags can be turned on using the values 1, [0m[1;31mOn[0m, True or Yes.
|
||
|
||
; sign, or by using the None keyword:
|
||
|
||
; foo = None ; sets foo to an empty string
|
||
|
||
; foo = "None" ; sets foo to the string 'None'
|
||
|
||
; If you use constants in your value, and these constants belong to a
|
||
|
||
; dynamically loaded extension (either a PHP extension or a Zend extension),
|
||
|
||
; you may only use these constants *after* the line that loads the extension.
|
||
|
||
; PHP comes packaged with two INI files. [0m[1;31mOn[0me that is recommended to be used
|
||
|
||
; in production environments and one that is recommended to be used in
|
||
|
||
; development environments.
|
||
|
||
; php.ini-production contains settings which hold security, performance and
|
||
|
||
; compatibility with older or less security conscience applications. We
|
||
|
||
; recommending using the production ini in production and testing environments.
|
||
|
||
; php.ini-development is very similar to its production variant, except it is
|
||
|
||
; development version only in development environments, as errors shown to
|
||
|
||
; application users can inadvertently leak otherwise secure information.
|
||
|
||
; The following are all the settings which are different in either the production
|
||
|
||
; or development versions of the INIs with respect to PHP's default behavior.
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
; Production Value: E_ALL & ~E_DEPRECATED & ~E_STRICT
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: [0m[1;31mOn[0m
|
||
|
||
; Development Value: 60 (60 seconds)
|
||
|
||
; Production Value: 60 (60 seconds)
|
||
|
||
; Production Value: 4096
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
; Default Value: None
|
||
|
||
; Production Value: "GP"
|
||
|
||
; session.gc_divisor
|
||
|
||
; Production Value: 1000
|
||
|
||
; session.sid_bits_per_character
|
||
|
||
; Production Value: 5
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
; Production Value: "GPCS"
|
||
|
||
; zend.exception_ignore_args
|
||
|
||
; Production Value: [0m[1;31mOn[0m
|
||
|
||
; zend.exception_string_param_max_len
|
||
|
||
; Production Value: 0
|
||
|
||
; php.ini Options ;
|
||
|
||
; To disable this feature set this option to an empty value
|
||
|
||
; TTL for user-defined php.ini files (time-to-live) in seconds. Default is 300 seconds (5 minutes)
|
||
|
||
; Language Options ;
|
||
|
||
engine = [0m[1;31mOn[0m
|
||
|
||
; documents, however this remains supported for backward compatibility reasons.
|
||
|
||
; Note that this directive does not control the <?= shorthand tag, which can be
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
; https://php.net/precision
|
||
|
||
precision = 14
|
||
|
||
; Output buffering is a mechanism for controlling how much output data
|
||
|
||
; data to the client. If your application's output exceeds this setting, PHP
|
||
|
||
; Turning on this setting and managing its maximum buffer size can yield some
|
||
|
||
; interesting side-effects depending on your application and web server.
|
||
|
||
; as it gets it. [0m[1;31mOn[0m production servers, 4096 bytes is a good setting for performance
|
||
|
||
; reasons.
|
||
|
||
; Note: Output buffering can also be controlled via Output Buffering Control
|
||
|
||
; functions.
|
||
|
||
; [0m[1;31mOn[0m = Enabled and buffer is unlimited. (Use with caution)
|
||
|
||
; Production Value: 4096
|
||
|
||
; You can redirect all of the output of your scripts to a function. For
|
||
|
||
; encoding will be transparently converted to the specified encoding.
|
||
|
||
; Setting any output handler automatically turns on output buffering.
|
||
|
||
; Note: People who wrote portable scripts should not depend on this ini
|
||
|
||
; Note: You cannot use both "mb_output_handler" with "ob_iconv_handler"
|
||
|
||
; and you cannot use both "ob_gzhandler" and "zlib.output_compression".
|
||
|
||
; Note: output_handler must be empty if this is set '[0m[1;31mOn[0m' !!!!
|
||
|
||
; URL rewriter function rewrites URL on the fly by using
|
||
|
||
; output buffer. You can set target tags by this configuration.
|
||
|
||
; Refer to session.trans_sid_tags for usage.
|
||
|
||
; Production Value: "form="
|
||
|
||
; Refer to session.trans_sid_hosts for more details.
|
||
|
||
; Production Value: ""
|
||
|
||
; Transparent output compression using the zlib library
|
||
|
||
; Valid values for this option are 'off', 'on', or a specific buffer size
|
||
|
||
; to be used for compression (default is 4KB)
|
||
|
||
; Note: Resulting chunk size may vary due to nature of compression. PHP
|
||
|
||
; compression. If you prefer a larger chunk size for better
|
||
|
||
; performance, enable output_buffering in addition.
|
||
|
||
; https://php.net/zlib.output-compression
|
||
|
||
zlib.output_compression = Off
|
||
|
||
; https://php.net/zlib.output-compression-level
|
||
|
||
;zlib.output_compression_level = -1
|
||
|
||
; You cannot specify additional output handlers if zlib.output_compression
|
||
|
||
; PHP function flush() after each and every call to print() or echo() and each
|
||
|
||
; and every HTML block. Turning this option on has serious performance
|
||
|
||
; implications and is generally recommended for debugging purposes only.
|
||
|
||
; Note: This directive is hardcoded to [0m[1;31mOn[0m for the CLI SAPI
|
||
|
||
; The unserialize callback function will be called (with the undefined class'
|
||
|
||
; which should be instantiated. A warning appears if the specified function is
|
||
|
||
; not defined, or if the function doesn't include/implement the missing class.
|
||
|
||
; So only set this entry, if you really want to implement such a
|
||
|
||
; callback-function.
|
||
|
||
; during unserialization. The unserialize_max_depth ini setting can be
|
||
|
||
; overridden by the max_depth option on individual unserialize() calls.
|
||
|
||
; When floats & doubles are serialized, store serialize_precision significant
|
||
|
||
; The value is also used for json_encode when encoding double values.
|
||
|
||
; precision.
|
||
|
||
serialize_precision = -1
|
||
|
||
; open_basedir, if set, limits all file operations to the defined directory
|
||
|
||
; or per-virtualhost web server configuration file.
|
||
|
||
; This directive allows you to disable certain functions.
|
||
|
||
; It receives a comma-delimited list of function names.
|
||
|
||
; https://php.net/disable-functions
|
||
|
||
disable_functions =
|
||
|
||
; the request. Consider enabling it if executing long requests, which may end up
|
||
|
||
;ignore_user_abort = [0m[1;31mOn[0m
|
||
|
||
; be increased on systems where PHP opens many files to reflect the quantity of
|
||
|
||
; the file operations performed.
|
||
|
||
; Duration of time, in seconds for which to cache realpath information for a given
|
||
|
||
; file or directory. For systems with rarely changing files, consider increasing this
|
||
|
||
zend.enable_gc = [0m[1;31mOn[0m
|
||
|
||
; encodings. To use this feature, mbstring extension must be enabled.
|
||
|
||
; [0m[1;31mOn[0mly affects if zend.multibyte is set.
|
||
|
||
; Allows to include or exclude arguments from stack traces generated for exceptions.
|
||
|
||
; In production, it is recommended to turn this setting on to prohibit the output
|
||
|
||
; of sensitive information in stack traces
|
||
|
||
; Production Value: [0m[1;31mOn[0m
|
||
|
||
zend.exception_ignore_args = Off
|
||
|
||
; This has no effect when zend.exception_ignore_args is enabled.
|
||
|
||
; Production Value: 0
|
||
|
||
zend.exception_string_param_max_len = 15
|
||
|
||
; Decides whether PHP may expose the fact that it is installed on the server
|
||
|
||
; on your server or not.
|
||
|
||
expose_php = [0m[1;31mOn[0m
|
||
|
||
; Maximum execution time of each script, in seconds
|
||
|
||
; https://php.net/max-execution-time
|
||
|
||
max_execution_time = 120
|
||
|
||
; idea to limit this time on productions servers in order to eliminate unexpectedly
|
||
|
||
; long running scripts.
|
||
|
||
; Development Value: 60 (60 seconds)
|
||
|
||
; Production Value: 60 (60 seconds)
|
||
|
||
; Maximum amount of memory a script may consume
|
||
|
||
; it to take action for. The recommended way of setting values for this
|
||
|
||
; directive is through the use of the error level constants and bitwise
|
||
|
||
; operators. The error level constants are below here for convenience as well as
|
||
|
||
; some common settings and their meanings.
|
||
|
||
; By default, PHP is set to take action on all errors, notices and warnings EXCEPT
|
||
|
||
; recommended coding standards in PHP. For performance reasons, this is the
|
||
|
||
; recommend error reporting setting. Your production server shouldn't be wasting
|
||
|
||
; Error Level Constants:
|
||
|
||
; E_WARNING - run-time warnings (non-fatal errors)
|
||
|
||
; intentional (e.g., using an uninitialized variable and
|
||
|
||
; relying on the fact it is automatically initialized to an
|
||
|
||
; E_CORE_WARNING - warnings (non-fatal errors) that occur during PHP's
|
||
|
||
; E_COMPILE_WARNING - compile-time warnings (non-fatal errors)
|
||
|
||
; E_DEPRECATED - warn about code that will not work in future versions
|
||
|
||
; E_USER_DEPRECATED - user-generated deprecation warnings
|
||
|
||
; Common Values:
|
||
|
||
; E_COMPILE_ERROR|E_RECOVERABLE_ERROR|E_ERROR|E_CORE_ERROR (Show only errors)
|
||
|
||
; Production Value: E_ALL & ~E_DEPRECATED & ~E_STRICT
|
||
|
||
; This directive controls whether or not and where PHP will output errors,
|
||
|
||
; it could be very dangerous in production environments. Depending on the code
|
||
|
||
; which is triggering the error, sensitive information could potentially leak
|
||
|
||
; out of your application such as database usernames and passwords or worse.
|
||
|
||
; For production environments, we recommend logging errors rather than
|
||
|
||
; stderr = Display errors to STDERR (affects only CGI/CLI binaries!)
|
||
|
||
; [0m[1;31mOn[0m or stdout = Display errors to STDOUT
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
display_errors = [0m[1;31mOn[0m
|
||
|
||
; separately from display_errors. We strongly recommend you set this to 'off'
|
||
|
||
; for production servers to avoid leaking configuration details.
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
display_startup_errors = [0m[1;31mOn[0m
|
||
|
||
; Besides displaying errors, PHP can also log errors to locations such as a
|
||
|
||
; server-specific log, STDERR, or a location specified by the error_log
|
||
|
||
; directive found below. While errors should not be displayed on productions
|
||
|
||
; servers they should still be monitored and logging is a great way to do that.
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: [0m[1;31mOn[0m
|
||
|
||
log_errors = [0m[1;31mOn[0m
|
||
|
||
; Do not log repeated messages. Repeated errors must occur in same file on same
|
||
|
||
; is [0m[1;31mOn[0m you will not log errors with repeated messages from different files or
|
||
|
||
; If this parameter is set to Off, then memory leaks will not be shown (on
|
||
|
||
; stdout or in the log). This is only effective in a debug compile, and if
|
||
|
||
report_memleaks = [0m[1;31mOn[0m
|
||
|
||
; error message as HTML for easier reading. This directive controls whether
|
||
|
||
;html_errors = [0m[1;31mOn[0m
|
||
|
||
; If html_errors is set to [0m[1;31mOn[0m *and* docref_root is not empty, then PHP
|
||
|
||
; or function causing the error in detail.
|
||
|
||
; leading '/'. You must also specify the file extension being used including
|
||
|
||
; case no links to documentation are generated.
|
||
|
||
; Note: Never use this feature for production boxes.
|
||
|
||
; Log errors to syslog (Event Log on Windows).
|
||
|
||
; to syslog. [0m[1;31mOn[0mly used when error_log is set to syslog.
|
||
|
||
; the message. [0m[1;31mOn[0mly used when error_log is set to syslog.
|
||
|
||
; Set this to disable filtering control characters (the default).
|
||
|
||
; Some loggers only accept NVT-ASCII, others accept anything that's not
|
||
|
||
; control characters. If your logger accepts everything, then no filtering
|
||
|
||
; no-ctrl (all characters except control characters)
|
||
|
||
; Production value: 0
|
||
|
||
; NOTE: Every character in this directive is considered as separator!
|
||
|
||
; starts up. G,P,C,E & S are abbreviations for the following respective super
|
||
|
||
; paid for the registration of these arrays and because ENV is not as commonly
|
||
|
||
; used as the others, ENV is not recommended on productions servers. You
|
||
|
||
; can still get access to the environment variables through getenv() should you
|
||
|
||
; Production Value: "GPCS";
|
||
|
||
; EXCEPT one. Leaving this value empty will cause PHP to use the value set
|
||
|
||
; Default Value: None
|
||
|
||
; Production Value: "GP"
|
||
|
||
; runs. $argv contains an array of all the arguments passed to PHP when a script
|
||
|
||
; is invoked. $argc contains an integer representing the number of arguments
|
||
|
||
; enabled, registering these variables consumes CPU cycles and memory each time
|
||
|
||
; a script is executed. For performance reasons, this feature should be disabled
|
||
|
||
; on production servers.
|
||
|
||
; Note: This directive is hardcoded to [0m[1;31mOn[0m for the CLI SAPI
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: Off
|
||
|
||
; variables are not used within a script, having this directive on will result
|
||
|
||
auto_globals_jit = [0m[1;31mOn[0m
|
||
|
||
; This option is enabled by default.
|
||
|
||
; Most likely, you won't want to disable this option globally. It causes $_POST
|
||
|
||
; and $_FILES to always be empty; the only way you will be able to read the
|
||
|
||
; to proxy requests or to process the POST data in a memory efficient fashion.
|
||
|
||
; By default, PHP will output a media type using the Content-Type header. To
|
||
|
||
; The root of the PHP pages, used only if nonempty.
|
||
|
||
; see documentation for security issues. The alternate is to use the
|
||
|
||
; cgi.force_redirect configuration below
|
||
|
||
; The directory under which PHP opens the script using /~username used only
|
||
|
||
; if nonempty.
|
||
|
||
; Directory in which the loadable extensions (modules) reside.
|
||
|
||
; https://php.net/extension-dir
|
||
|
||
;extension_dir = "./"
|
||
|
||
; [0m[1;31mOn[0m windows:
|
||
|
||
extension_dir = "\xampp\php\ext"
|
||
|
||
; Whether or not to enable the dl() function. The dl() function does NOT work
|
||
|
||
; disabled on them.
|
||
|
||
; most web servers. Left undefined, PHP turns this on by default. You can
|
||
|
||
; if cgi.force_redirect is turned on, and you are not running under Apache or Netscape
|
||
|
||
; (iPlanet) web servers, you MAY need to set an environment variable name that PHP
|
||
|
||
; will look for to know it is OK to continue execution. Setting this variable MAY
|
||
|
||
; what PATH_INFO is. For more information on PATH_INFO, see the cgi specs. Setting
|
||
|
||
; this to 1 will cause PHP CGI to fix its paths to conform to the spec. A setting
|
||
|
||
; FastCGI under IIS supports the ability to impersonate
|
||
|
||
; security context that the request runs under. mod_fastcgi under Apache
|
||
|
||
; https://php.net/fastcgi.impersonate
|
||
|
||
;fastcgi.impersonate = 1
|
||
|
||
; Disable logging through FastCGI connection. PHP's default behavior is to enable
|
||
|
||
; cgi.rfc2616_headers configuration option tells PHP what type of headers to
|
||
|
||
; use when sending HTTP response code. If set to 0, PHP sends Status: header that
|
||
|
||
; is supported by Apache. When this option is set to 1, PHP will send
|
||
|
||
; cgi.check_shebang_line controls whether CGI PHP checks for line starting with #!
|
||
|
||
; script support running both as stand-alone script and via PHP CGI<. PHP in CGI
|
||
|
||
; mode skips this line and ignores its content if this directive is turned on.
|
||
|
||
file_uploads = [0m[1;31mOn[0m
|
||
|
||
allow_url_fopen = [0m[1;31mOn[0m
|
||
|
||
; Define the anonymous ftp password (your email address). PHP's default setting
|
||
|
||
; Default timeout for socket based streams (seconds)
|
||
|
||
; or you are running on a Mac and need to deal with files from
|
||
|
||
; Dynamic Extensions ;
|
||
|
||
; If you wish to have an extension loaded automatically, use the following
|
||
|
||
; extension=modulename
|
||
|
||
; extension=mysqli
|
||
|
||
; When the extension library to load is not located in the default extension
|
||
|
||
; extension=/path/to/extension/mysqli.so
|
||
|
||
; Note : The syntax used in previous PHP versions ('extension=<ext>.so' and
|
||
|
||
; 'extension='php_<ext>.dll') is supported for legacy reasons and may be
|
||
|
||
; deprecated in a future PHP major version. So, when it is possible, please
|
||
|
||
; move to the new ('extension=<ext>) syntax.
|
||
|
||
; Notes for Windows environments :
|
||
|
||
; - Many DLL files are located in the extensions/ (PHP 4) or ext/ (PHP 5+)
|
||
|
||
; extension folders as well as the separate PECL DLL download (PHP 5+).
|
||
|
||
; Be sure to appropriately set the extension_dir directive.
|
||
|
||
extension=bz2
|
||
|
||
extension=curl
|
||
|
||
;extension=ffi
|
||
|
||
;extension=ftp
|
||
|
||
extension=fileinfo
|
||
|
||
;extension=gd
|
||
|
||
extension=gettext
|
||
|
||
;extension=gmp
|
||
|
||
;extension=intl
|
||
|
||
;extension=imap
|
||
|
||
;extension=ldap
|
||
|
||
extension=mbstring
|
||
|
||
extension=exif ; Must be after mbstring as it depends on it
|
||
|
||
extension=mysqli
|
||
|
||
;extension=oci8_12c ; Use with Oracle Database 12c Instant Client
|
||
|
||
;extension=oci8_19 ; Use with Oracle Database 19 Instant Client
|
||
|
||
;extension=odbc
|
||
|
||
;extension=openssl
|
||
|
||
;extension=pdo_firebird
|
||
|
||
extension=pdo_mysql
|
||
|
||
;extension=pdo_oci
|
||
|
||
;extension=pdo_odbc
|
||
|
||
;extension=pdo_pgsql
|
||
|
||
extension=pdo_sqlite
|
||
|
||
;extension=pgsql
|
||
|
||
;extension=shmop
|
||
|
||
; The MIBS data available in the PHP distribution must be installed.
|
||
|
||
; See https://www.php.net/manual/en/snmp.installation.php
|
||
|
||
;extension=snmp
|
||
|
||
;extension=soap
|
||
|
||
;extension=sockets
|
||
|
||
;extension=sodium
|
||
|
||
;extension=sqlite3
|
||
|
||
;extension=tidy
|
||
|
||
;extension=xsl
|
||
|
||
;zend_extension=opcache
|
||
|
||
display_startup_errors=[0m[1;31mOn[0m
|
||
|
||
y2k_compliance=[0m[1;31mOn[0m
|
||
|
||
register_long_arrays=Off
|
||
|
||
extension=php_openssl.dll
|
||
|
||
extension=php_ftp.dll
|
||
|
||
cli_server.color = [0m[1;31mOn[0m
|
||
|
||
; Defines the default timezone used by the date functions
|
||
|
||
; https://php.net/date.timezone
|
||
|
||
;date.timezone =
|
||
|
||
; https://php.net/date.default-longitude
|
||
|
||
;date.default_longitude = 35.2333
|
||
|
||
[iconv]
|
||
|
||
; If empty, default_charset or input_encoding or iconv.input_encoding is used.
|
||
|
||
; The precedence is: default_charset < input_encoding < iconv.input_encoding
|
||
|
||
;iconv.input_encoding =
|
||
|
||
; If empty, default_charset or internal_encoding or iconv.internal_encoding is used.
|
||
|
||
; The precedence is: default_charset < internal_encoding < iconv.internal_encoding
|
||
|
||
;iconv.internal_encoding =
|
||
|
||
; If empty, default_charset or output_encoding or iconv.output_encoding is used.
|
||
|
||
; The precedence is: default_charset < output_encoding < iconv.output_encoding
|
||
|
||
; To use an output encoding conversion, iconv's output handler must be set
|
||
|
||
; otherwise output encoding conversion cannot be performed.
|
||
|
||
;iconv.output_encoding =
|
||
|
||
; passing them to rsh/ssh command, thus passing untrusted data to this function
|
||
|
||
; happens within intl functions. The value is the level of the error produced.
|
||
|
||
;intl.use_exceptions = 0
|
||
|
||
; Directory pointing to SQLite3 extensions
|
||
|
||
; https://php.net/sqlite3.extension-dir
|
||
|
||
;sqlite3.extension_dir =
|
||
|
||
; SQLite defensive mode flag (only available from SQLite 3.26+)
|
||
|
||
; https://www.sqlite.org/c3ref/c_dbconfig_defensive.html
|
||
|
||
; (for older SQLite versions, this flag has no use)
|
||
|
||
; PCRE library recursion limit.
|
||
|
||
; Please note that if you set this value to a high number you may consume all
|
||
|
||
; https://php.net/pcre.recursion-limit
|
||
|
||
;pcre.recursion_limit=100000
|
||
|
||
; Enables or disables JIT compilation of patterns. This requires the PCRE
|
||
|
||
; Whether to pool ODBC connections. Can be one of "strict", "relaxed" or "off"
|
||
|
||
; https://php.net/pdo-odbc.connection-pooling
|
||
|
||
;pdo_odbc.connection_pooling=strict
|
||
|
||
; Default socket name for local MySQL connects. If empty, uses the built-in
|
||
|
||
; https://php.net/phar.readonly
|
||
|
||
;phar.readonly = [0m[1;31mOn[0m
|
||
|
||
;phar.require_hash = [0m[1;31mOn[0m
|
||
|
||
[mail function]
|
||
|
||
; For Win32 only.
|
||
|
||
; For Win32 only.
|
||
|
||
; For Unix only. You may supply arguments as well (default: "sendmail -t -i").
|
||
|
||
; Force the addition of the specified parameters to be passed as extra parameters
|
||
|
||
; Log mail to syslog (Event Log on Windows).
|
||
|
||
; Controls the ODBC cursor model.
|
||
|
||
odbc.allow_persistent = [0m[1;31mOn[0m
|
||
|
||
; Check that a connection is still valid before reuse.
|
||
|
||
odbc.check_persistent = [0m[1;31mOn[0m
|
||
|
||
; Maximum number of links (persistent + non-persistent). -1 means no limit.
|
||
|
||
; Handling of LONG fields. Returns number of bytes to variables. 0 means
|
||
|
||
; Handling of binary data. 0 means passthru, 1 return as is, 2 convert to char.
|
||
|
||
; See the documentation on odbc_binmode and odbc_longreadlen for an explanation
|
||
|
||
;mysqli.allow_local_infile = [0m[1;31mOn[0m
|
||
|
||
mysqli.allow_persistent = [0m[1;31mOn[0m
|
||
|
||
; Default port number for mysqli_connect(). If unset, mysqli_connect() will use
|
||
|
||
; compile-time value defined MYSQL_PORT (in that order). Win32 will only look
|
||
|
||
; Default socket name for local MySQL connects. If empty, uses the built-in
|
||
|
||
; Default host for mysqli_connect() (doesn't apply in safe mode).
|
||
|
||
; Default user for mysqli_connect() (doesn't apply in safe mode).
|
||
|
||
; Default password for mysqli_connect() (doesn't apply in safe mode).
|
||
|
||
; Allow or prevent reconnect
|
||
|
||
mysqli.reconnect = Off
|
||
|
||
; If this option is enabled, closing a persistent connection will rollback
|
||
|
||
; any pending transactions of this connection, before it is put back
|
||
|
||
; into the persistent connection pool.
|
||
|
||
;mysqli.rollback_on_cached_plink = Off
|
||
|
||
; Enable / Disable collection of general statistics by mysqlnd which can be
|
||
|
||
; used to tune and monitor MySQL operations.
|
||
|
||
mysqlnd.collect_statistics = [0m[1;31mOn[0m
|
||
|
||
; Enable / Disable collection of memory usage statistics by mysqlnd which can be
|
||
|
||
; used to tune and monitor MySQL operations.
|
||
|
||
mysqlnd.collect_memory_statistics = [0m[1;31mOn[0m
|
||
|
||
; Records communication from all extensions using mysqlnd to the specified log
|
||
|
||
; Timeout for network requests in seconds.
|
||
|
||
; SHA-256 Authentication Plugin related. File with the MySQL server public RSA
|
||
|
||
; Connection: Enables privileged connections using external
|
||
|
||
; https://php.net/oci8.privileged-connect
|
||
|
||
;oci8.privileged_connect = Off
|
||
|
||
; Connection: The maximum number of persistent OCI8 connections per
|
||
|
||
; Connection: The maximum number of seconds a process is allowed to
|
||
|
||
; maintain an idle persistent connection. Using -1 means idle
|
||
|
||
; persistent connections will be maintained forever.
|
||
|
||
; Connection: The number of seconds that must pass before issuing a
|
||
|
||
; ping during oci_pconnect() to check the connection validity. When
|
||
|
||
; set to 0, each oci_pconnect() will cause a ping. Using -1 disables
|
||
|
||
; Connection: Set this to a user chosen connection class to be used
|
||
|
||
; Connection Pooling (DRCP). To use DRCP, this value should be set to
|
||
|
||
; the same string for all web servers running the same application,
|
||
|
||
; the database pool must be configured, and the connection string must
|
||
|
||
;oci8.connection_class =
|
||
|
||
; High Availability: Using [0m[1;31mOn[0m lets PHP receive Fast Application
|
||
|
||
; Notification (FAN) events generated when a database node fails. The
|
||
|
||
; database must also be configured to post FAN events.
|
||
|
||
; Tuning: This option enables statement caching, and specifies how
|
||
|
||
; rows that will be fetched automatically after statement execution.
|
||
|
||
; Compatibility. Using [0m[1;31mOn[0m means oci_close() will not close
|
||
|
||
; oci_connect() and oci_new_connect() connections.
|
||
|
||
pgsql.allow_persistent = [0m[1;31mOn[0m
|
||
|
||
; Detect broken persistent links always with pg_pconnect().
|
||
|
||
; Maximum number of links (persistent+non persistent). -1 means no limit.
|
||
|
||
; Number of decimal digits for all bcmath functions.
|
||
|
||
[Session]
|
||
|
||
; https://php.net/session.save-handler
|
||
|
||
session.save_handler = files
|
||
|
||
; variable in order to use PHP's session functions.
|
||
|
||
; session.save_path = "N;/path"
|
||
|
||
; where N is an integer. Instead of storing all the session files in
|
||
|
||
; store the session data in those directories. This is useful if
|
||
|
||
; your OS has problems with many files in one directory, and is
|
||
|
||
; a more efficient layout for servers that handle many sessions.
|
||
|
||
; You can use the script in the ext/session dir for that purpose.
|
||
|
||
; NOTE 2: See the section on garbage collection below if you choose to
|
||
|
||
; use subdirectories for session storage
|
||
|
||
; session.save_path = "N;MODE;/path"
|
||
|
||
; where MODE is the octal representation of the mode. Note that this
|
||
|
||
; https://php.net/session.save-path
|
||
|
||
session.save_path = "\xampp\tmp"
|
||
|
||
; Whether to use strict session mode.
|
||
|
||
; Strict session mode does not accept an uninitialized session ID, and
|
||
|
||
; regenerates the session ID if the browser sends an uninitialized session ID.
|
||
|
||
; Strict mode protects applications from session fixation via a session adoption
|
||
|
||
; https://wiki.php.net/rfc/strict_sessions
|
||
|
||
session.use_strict_mode = 0
|
||
|
||
; https://php.net/session.use-cookies
|
||
|
||
session.use_cookies = 1
|
||
|
||
; https://php.net/session.cookie-secure
|
||
|
||
;session.cookie_secure =
|
||
|
||
; This option forces PHP to fetch and use a cookie for storing and maintaining
|
||
|
||
; the session id. We encourage this operation as it's very helpful in combating
|
||
|
||
; session hijacking when not specifying and managing your own session id. It is
|
||
|
||
; not the be-all and end-all of session hijacking defense, but it's a good start.
|
||
|
||
; https://php.net/session.use-only-cookies
|
||
|
||
session.use_only_cookies = 1
|
||
|
||
; Name of the session (used as cookie name).
|
||
|
||
; https://php.net/session.name
|
||
|
||
session.name = PHPSESSID
|
||
|
||
; Initialize session on request startup.
|
||
|
||
; https://php.net/session.auto-start
|
||
|
||
session.auto_start = 0
|
||
|
||
; Lifetime in seconds of cookie or, if 0, until browser is restarted.
|
||
|
||
; https://php.net/session.cookie-lifetime
|
||
|
||
session.cookie_lifetime = 0
|
||
|
||
; https://php.net/session.cookie-path
|
||
|
||
session.cookie_path = /
|
||
|
||
; https://php.net/session.cookie-domain
|
||
|
||
session.cookie_domain =
|
||
|
||
; Whether or not to add the http[0m[1;31mOn[0mly flag to the cookie, which makes it
|
||
|
||
; https://php.net/session.cookie-httponly
|
||
|
||
session.cookie_httponly =
|
||
|
||
; Current valid values are "Strict", "Lax" or "None". When using "None",
|
||
|
||
; make sure to include the quotes, as `none` is interpreted like `false` in ini files.
|
||
|
||
session.cookie_samesite =
|
||
|
||
; https://php.net/session.serialize-handler
|
||
|
||
session.serialize_handler = php
|
||
|
||
; Defines the probability that the 'garbage collection' process is started on every
|
||
|
||
; session initialization. The probability is calculated by using gc_probability/gc_divisor,
|
||
|
||
; e.g. 1/100 means there is a 1% chance that the GC process starts on each request.
|
||
|
||
; Production Value: 1
|
||
|
||
; https://php.net/session.gc-probability
|
||
|
||
session.gc_probability = 1
|
||
|
||
; Defines the probability that the 'garbage collection' process is started on every
|
||
|
||
; session initialization. The probability is calculated by using gc_probability/gc_divisor,
|
||
|
||
; e.g. 1/100 means there is a 1% chance that the GC process starts on each request.
|
||
|
||
; For high volume production servers, using a value of 1000 is a more efficient approach.
|
||
|
||
; Production Value: 1000
|
||
|
||
; https://php.net/session.gc-divisor
|
||
|
||
session.gc_divisor = 1000
|
||
|
||
; After this number of seconds, stored data will be seen as 'garbage' and
|
||
|
||
; cleaned up by the garbage collection process.
|
||
|
||
; https://php.net/session.gc-maxlifetime
|
||
|
||
session.gc_maxlifetime = 1440
|
||
|
||
; NOTE: If you are using the subdirectory option for storing session files
|
||
|
||
; (see session.save_path above), then garbage collection does *not*
|
||
|
||
; collection through a shell script, cron entry, or some other method.
|
||
|
||
; session.gc_maxlifetime to 1440 (1440 seconds = 24 minutes):
|
||
|
||
; find /path/to/sessions -cmin +24 -type f | xargs rm
|
||
|
||
; Check HTTP Referer to invalidate externally stored URLs containing ids.
|
||
|
||
; HTTP_REFERER has to contain this substring for the session to be
|
||
|
||
; considered as valid.
|
||
|
||
; https://php.net/session.referer-check
|
||
|
||
session.referer_check =
|
||
|
||
; https://php.net/session.cache-limiter
|
||
|
||
session.cache_limiter = nocache
|
||
|
||
; https://php.net/session.cache-expire
|
||
|
||
session.cache_expire = 180
|
||
|
||
; Use this option with caution.
|
||
|
||
; - User may send URL contains active session ID
|
||
|
||
; to other person via. email/irc/etc.
|
||
|
||
; - URL that contains active session ID may be stored
|
||
|
||
; - User may access your site with the same session ID
|
||
|
||
; https://php.net/session.use-trans-sid
|
||
|
||
session.use_trans_sid = 0
|
||
|
||
; Set session ID character length. This value could be between 22 to 256.
|
||
|
||
; Shorter length than default is supported only for compatibility reason.
|
||
|
||
; https://php.net/session.sid-length
|
||
|
||
; Production Value: 26
|
||
|
||
session.sid_length = 26
|
||
|
||
; to URLs. <form> tag's action attribute URL will not be modified
|
||
|
||
; Production Value: "a=href,area=href,frame=src,form="
|
||
|
||
session.trans_sid_tags = "a=href,area=href,frame=src,form="
|
||
|
||
; <form> tags is special. PHP will check action attribute's URL regardless
|
||
|
||
; of session.trans_sid_tags setting.
|
||
|
||
; Production Value: ""
|
||
|
||
;session.trans_sid_hosts=""
|
||
|
||
; Define how many bits are stored in each character when converting
|
||
|
||
; Production Value: 5
|
||
|
||
; https://php.net/session.hash-bits-per-character
|
||
|
||
session.sid_bits_per_character = 5
|
||
|
||
; Enable upload progress tracking in $_SESSION
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: [0m[1;31mOn[0m
|
||
|
||
; https://php.net/session.upload-progress.enabled
|
||
|
||
;session.upload_progress.enabled = [0m[1;31mOn[0m
|
||
|
||
; Cleanup the progress information as soon as all POST data has been read
|
||
|
||
; Default Value: [0m[1;31mOn[0m
|
||
|
||
; Development Value: [0m[1;31mOn[0m
|
||
|
||
; Production Value: [0m[1;31mOn[0m
|
||
|
||
; https://php.net/session.upload-progress.cleanup
|
||
|
||
;session.upload_progress.cleanup = [0m[1;31mOn[0m
|
||
|
||
; A prefix used for the upload progress key in $_SESSION
|
||
|
||
; Production Value: "upload_progress_"
|
||
|
||
; https://php.net/session.upload-progress.prefix
|
||
|
||
;session.upload_progress.prefix = "upload_progress_"
|
||
|
||
; The index name (concatenated with the prefix) in $_SESSION
|
||
|
||
; containing the upload progress information
|
||
|
||
; Default Value: "PHP_SESSION_UPLOAD_PROGRESS"
|
||
|
||
; Development Value: "PHP_SESSION_UPLOAD_PROGRESS"
|
||
|
||
; Production Value: "PHP_SESSION_UPLOAD_PROGRESS"
|
||
|
||
; https://php.net/session.upload-progress.name
|
||
|
||
;session.upload_progress.name = "PHP_SESSION_UPLOAD_PROGRESS"
|
||
|
||
; Production Value: "1%"
|
||
|
||
; https://php.net/session.upload-progress.freq
|
||
|
||
;session.upload_progress.freq = "1%"
|
||
|
||
; The minimum delay between updates, in seconds
|
||
|
||
; Production Value: 1
|
||
|
||
; https://php.net/session.upload-progress.min-freq
|
||
|
||
;session.upload_progress.min_freq = "1"
|
||
|
||
; [0m[1;31mOn[0mly write session data when session data is changed. Enabled by default.
|
||
|
||
; https://php.net/session.lazy-write
|
||
|
||
;session.lazy_write = [0m[1;31mOn[0m
|
||
|
||
[Assertion]
|
||
|
||
; Switch whether to compile assertions at all (to have no overhead at run-time)
|
||
|
||
; 0: Jump over assertion at run-time
|
||
|
||
; 1: Execute assertions
|
||
|
||
; Changing from or to a negative value is only possible in php.ini! (For turning assertions on and off at run-time, see assert.active, when zend.assertions = 1)
|
||
|
||
; Production Value: -1
|
||
|
||
; https://php.net/zend.assertions
|
||
|
||
zend.assertions = 1
|
||
|
||
;assert.active = [0m[1;31mOn[0m
|
||
|
||
; Throw an AssertionError on failed assertions
|
||
|
||
; https://php.net/assert.exception
|
||
|
||
;assert.exception = [0m[1;31mOn[0m
|
||
|
||
; Issue a PHP warning for each failed assertion. (Overridden by assert.exception if active)
|
||
|
||
;assert.warning = [0m[1;31mOn[0m
|
||
|
||
; Don't bail out by default.
|
||
|
||
; User-function to be called if an assertion fails.
|
||
|
||
; path to a file containing GUIDs, IIDs or filenames of files with TypeLibs
|
||
|
||
; autoregister constants of a component's typelib on com_load()
|
||
|
||
; register constants casesensitive
|
||
|
||
; show warnings on duplicate constant registrations
|
||
|
||
; The version of the .NET framework to use. The value of the setting are the first three parts
|
||
|
||
; of the framework's version number, separated by dots, and prefixed with "v", e.g. "v4.0.30319".
|
||
|
||
;com.dotnet_version=
|
||
|
||
; language for internal character representation.
|
||
|
||
; If empty, default_charset or internal_encoding or iconv.internal_encoding is used.
|
||
|
||
; The precedence is: default_charset < internal_encoding < iconv.internal_encoding
|
||
|
||
; mbstring.encoding_translation = [0m[1;31mOn[0m is needed to use this setting.
|
||
|
||
; mb_output_handler must be registered as output buffer to function.
|
||
|
||
; To use an output encoding conversion, mbstring's output handler must be set
|
||
|
||
; otherwise output encoding conversion cannot be performed.
|
||
|
||
; enable automatic encoding translation according to
|
||
|
||
; converted to internal encoding by setting this to [0m[1;31mOn[0m.
|
||
|
||
; Note: Do _not_ use automatic encoding translation for
|
||
|
||
; portable libs/applications.
|
||
|
||
; https://php.net/mbstring.encoding-translation
|
||
|
||
;mbstring.encoding_translation = Off
|
||
|
||
; automatic encoding detection order.
|
||
|
||
; substitute_character used when character cannot be converted
|
||
|
||
; one from another
|
||
|
||
;mbstring.substitute_character = none
|
||
|
||
; Enable strict encoding detection.
|
||
|
||
;mbstring.strict_detection = Off
|
||
|
||
; This directive specifies the regex pattern of content types for which mb_output_handler()
|
||
|
||
; Default: mbstring.http_output_conv_mimetypes=^(text/|application/xhtml\+xml)
|
||
|
||
;mbstring.http_output_conv_mimetypes=
|
||
|
||
; This directive specifies maximum stack depth for mbstring regular expressions. It is similar
|
||
|
||
; to the pcre.recursion_limit for PCRE.
|
||
|
||
; This directive specifies maximum retry count for mbstring regular expressions. It is similar
|
||
|
||
; With mbstring support this will automatically be converted into the encoding
|
||
|
||
; given by corresponding encode setting. When empty mbstring.internal_encoding
|
||
|
||
; The path to a default tidy configuration file to use when using tidy
|
||
|
||
; https://php.net/tidy.default-config
|
||
|
||
;tidy.default_config = /usr/local/lib/php/default.tcfg
|
||
|
||
; WARNING: Do not use this option if you are generating non-html content
|
||
|
||
; Sets the directory name where SOAP extension will put cache files.
|
||
|
||
; (time to live) Sets the number of second while cached file will be used
|
||
|
||
; instead of original one.
|
||
|
||
; Determines if Zend OPCache is enabled for the CLI version of PHP
|
||
|
||
;opcache.memory_consumption=128
|
||
|
||
; [0m[1;31mOn[0mly numbers between 200 and 1000000 are allowed.
|
||
|
||
; directory to the script key, thus eliminating possible collisions between
|
||
|
||
; performance, but may break existing applications.
|
||
|
||
; How often (in seconds) to check file timestamps for changes to the shared
|
||
|
||
; memory storage allocation. ("1" means validate once per second, but only
|
||
|
||
; once per request. "0" means always validate)
|
||
|
||
; Enables or disables file search in include_path optimization
|
||
|
||
; If enabled, compilation warnings (including notices and deprecations) will
|
||
|
||
; be recorded and replayed each time a file is included. Otherwise, compilation
|
||
|
||
; warnings will only be emitted when the file is first cached.
|
||
|
||
;opcache.optimization_level=0x7FFFBFFF
|
||
|
||
; The location of the OPcache blacklist file (wildcards allowed).
|
||
|
||
; Allows exclusion of large files from being cached. By default all files
|
||
|
||
;opcache.consistency_checks=0
|
||
|
||
; How long to wait (in seconds) for a scheduled restart to begin if the cache
|
||
|
||
; By default, only fatal errors (level 0) or errors (level 1) are logged.
|
||
|
||
; Protect the shared memory from unexpected writing during script execution.
|
||
|
||
; Useful for internal debugging only.
|
||
|
||
; Allows calling OPcache API functions only from PHP scripts which path is
|
||
|
||
; started from specified string. The default "" means no restriction
|
||
|
||
; Mapping base of shared memory segments (for Windows only). All the PHP
|
||
|
||
; Facilitates multiple OPcache instances per user (for Windows only). All PHP
|
||
|
||
; Enables and sets the second level cache directory.
|
||
|
||
;opcache.file_cache_only=0
|
||
|
||
; Enables or disables checksum validation when script loaded from file cache.
|
||
|
||
;opcache.file_cache_consistency_checks=1
|
||
|
||
; Implies opcache.file_cache_only=1 for a certain process that failed to
|
||
|
||
; reattach to the shared memory (for Windows only). Explicitly enabled file
|
||
|
||
; This should improve performance, but requires appropriate OS configuration.
|
||
|
||
; Validate cached file permissions.
|
||
|
||
;opcache.validate_permission=0
|
||
|
||
; Prevent name collisions in chroot'ed environment.
|
||
|
||
; optimizations.
|
||
|
||
; Preloading code as root is not allowed for security reasons. This directive
|
||
|
||
; Prevents caching files that are less than this number of seconds old. It
|
||
|
||
; on your site are atomic, you may increase performance by setting it to "0".
|
||
|
||
;opcache.file_update_protection=2
|
||
|
||
; Absolute path used to store shared lockfiles (for *nix only).
|
||
|
||
; A default value for the CURLOPT_CAINFO option. This is required to be an
|
||
|
||
; The location of a Certificate Authority (CA) file on the local filesystem
|
||
|
||
; be overridden on a per-stream basis via the "cafile" SSL stream context
|
||
|
||
; option.
|
||
|
||
; this value may still be overridden on a per-stream basis via the "capath"
|
||
|
||
; SSL stream context option.
|
||
|
||
; FFI API restriction. Possible values:
|
||
|
||
[Session]
|
||
|
||
date.timezone=Europe/Berlin
|
||
|
||
mysql.allow_local_infile=[0m[1;31mOn[0m
|
||
|
||
mysql.allow_persistent=[0m[1;31mOn[0m
|
||
|
||
mysql.connect_timeout=3
|
||
|
||
sybct.allow_persistent=[0m[1;31mOn[0m
|
||
|
||
mssql.allow_persistent=[0m[1;31mOn[0m
|
||
|
||
mssql.secure_connection=Off
|
||
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFound PHP_files Files[0m
|
||
File: C:\xampp\php\scripts\[0m[1;31mconfigure.php[0m
|
||
File: C:\xampp\php\pear\PHPUnit\Util\[0m[1;31mConfiguration.php[0m
|
||
File: C:\xampp\php\pear\PHP\Debug\Renderer\HTML\[0m[1;31mTableConfig.php[0m
|
||
File: C:\xampp\php\pear\PHP\Debug\Renderer\HTML\[0m[1;31mDivConfig.php[0m
|
||
File: C:\xampp\php\pear\PEAR\[0m[1;31mConfig.php[0m
|
||
File: C:\xampp\php\pear\PEAR\Command\[0m[1;31mConfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\tecnickcom\tcpdf\[0m[1;31mtcpdf_autoconfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\tecnickcom\tcpdf\config\[0m[1;31mtcpdf_config.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mServicesConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mServiceConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mReferenceConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mPrototypeConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mParametersConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mInstanceofConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mInlineServiceConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mDefaultsConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mContainerConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mAliasConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mAbstractServiceConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\[0m[1;31mAbstractConfigurator.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\Traits\[0m[1;31mConfiguratorTrait.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Loader\Configurator\Traits\[0m[1;31mAutoconfigureTrait.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Extension\[0m[1;31mConfigurationExtensionInterface.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Compiler\[0m[1;31mPassConfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\dependency-injection\Compiler\[0m[1;31mMergeExtensionConfigurationPass.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\[0m[1;31mResourceCheckerConfigCacheFactory.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\[0m[1;31mResourceCheckerConfigCache.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\[0m[1;31mConfigCacheInterface.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\[0m[1;31mConfigCacheFactoryInterface.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\[0m[1;31mConfigCacheFactory.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\[0m[1;31mConfigCache.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\Definition\[0m[1;31mConfigurationInterface.php[0m
|
||
File: C:\xampp\phpMyAdmin\vendor\symfony\config\Definition\Exception\[0m[1;31mInvalidConfigurationException.php[0m
|
||
File: C:\xampp\phpMyAdmin\setup\[0m[1;31mconfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\[0m[1;31mvendor_config.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\[0m[1;31mconfig.values.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\[0m[1;31mconfig.default.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\[0m[1;31mConfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\Setup\[0m[1;31mConfigGenerator.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\Plugins\Auth\[0m[1;31mAuthenticationConfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\Controllers\[0m[1;31mConfigController.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\Controllers\Setup\[0m[1;31mConfigController.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\Config\[0m[1;31mServerConfigChecks.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\Config\[0m[1;31mConfigFile.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\Config\Forms\Setup\[0m[1;31mConfigForm.php[0m
|
||
File: C:\xampp\phpMyAdmin\examples\[0m[1;31mconfig.manyhosts.inc.php[0m
|
||
File: C:\xampp\phpMyAdmin\[0m[1;31mshow_config_errors.php[0m
|
||
File: C:\xampp\phpMyAdmin\[0m[1;31mconfig.sample.inc.php[0m
|
||
File: C:\xampp\phpMyAdmin\[0m[1;31mconfig.inc.php[0m
|
||
File: C:\xampp\php\pear\Table\[0m[1;31mStorage.php[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFound Moodle Files[0m
|
||
File: C:\xampp\php\pear\PEAR\[0m[1;31mConfig.php[0m
|
||
File: C:\xampp\php\pear\PEAR\Command\[0m[1;31mConfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\setup\[0m[1;31mconfig.php[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\classes\[0m[1;31mConfig.php[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFound Tomcat Files[0m
|
||
File: C:\xampp\tomcat\conf\[0m[1;31mtomcat-users.xml[0m
|
||
|
||
[1;36m<36><6D><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD><EFBFBD> [1;32mFound CERTSB4 Files[0m
|
||
File: C:\xampp\perl\vendor\lib\Mozilla\CA\[0m[1;31mcacert.pem[0m
|
||
File: C:\xampp\phpMyAdmin\libraries\certs\[0m[1;31mcacert.pem[0m
|
||
File: C:\xampp\apache\conf\[0m[1;31mssl.crt[0m
|
||
[----------] 0% |/-\1% |/2% -\|/3% -\|4% /5% -\6% |7% /-8% \9% |#---------] 10% /-\|/-\|1% /-\|2% /-3% \|/-4% \|/-5% \|/-\|/-6% \|/-\7% |/-\|8% / [1;90mError looking for regexes inside files: System.AggregateException: One or more errors occurred. ---> System.UnauthorizedAccessException: Access to the path 'C:\xampp\htdocs\flight.htb\winshell.php' is denied.
|
||
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)
|
||
at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
|
||
at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
|
||
at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize, Boolean checkHost)
|
||
at System.IO.File.InternalReadAllText(String path, Encoding encoding, Boolean checkHost)
|
||
at ij.f.d(hz A_0)
|
||
at System.Threading.Tasks.Parallel.<>c__DisplayClass17_0`1.<ForWorker>b__1()
|
||
at System.Threading.Tasks.Task.InnerInvokeWithArg(Task childTask)
|
||
at System.Threading.Tasks.Task.<>c__DisplayClass176_0.<ExecuteSelfReplicating>b__0(Object )
|
||
--- End of inner exception stack trace ---
|
||
at System.Threading.Tasks.Task.ThrowIfExceptional(Boolean includeTaskCanceledExceptions)
|
||
at System.Threading.Tasks.Task.Wait(Int32 millisecondsTimeout, CancellationToken cancellationToken)
|
||
at System.Threading.Tasks.Parallel.ForWorker[TLocal](Int32 fromInclusive, Int32 toExclusive, ParallelOptions parallelOptions, Action`1 body, Action`2 bodyWithState, Func`4 bodyWithLocal, Func`1 localInit, Action`1 localFinally)
|
||
at System.Threading.Tasks.Parallel.ForEachWorker[TSource,TLocal](IEnumerable`1 source, ParallelOptions parallelOptions, Action`1 body, Action`2 bodyWithState, Action`3 bodyWithStateAndIndex, Func`4 bodyWithStateAndLocal, Func`5 bodyWithEverything, Func`1 localInit, Action`1 localFinally)
|
||
at System.Threading.Tasks.Parallel.ForEach[TSource](IEnumerable`1 source, ParallelOptions parallelOptions, Action`1 body)
|
||
at ij.f.d()
|
||
at h5.a(Action A_0, Boolean A_1, String A_2)
|
||
at ij.a()
|
||
---> (Inner Exception #0) System.UnauthorizedAccessException: Access to the path 'C:\xampp\htdocs\flight.htb\winshell.php' is denied.
|
||
at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath)
|
||
at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
|
||
at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost)
|
||
at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks, Int32 bufferSize, Boolean checkHost)
|
||
at System.IO.File.InternalReadAllText(String path, Encoding encoding, Boolean checkHost)
|
||
at ij.f.d(hz A_0)
|
||
at System.Threading.Tasks.Parallel.<>c__DisplayClass17_0`1.<ForWorker>b__1()
|
||
at System.Threading.Tasks.Task.InnerInvokeWithArg(Task childTask)
|
||
at System.Threading.Tasks.Task.<>c__DisplayClass176_0.<ExecuteSelfReplicating>b__0(Object )<---
|
||
[0m
|
||
[1;32m
|
||
/---------------------------------------------------------------------------------\
|
||
| [34mDo you like PEASS?[1;32m |
|
||
|---------------------------------------------------------------------------------|
|
||
| [33mGet the latest version[1;32m : [1;31mhttps://github.com/sponsors/carlospolop[1;32m |
|
||
| [33mFollow on Twitter[1;32m : [1;31m@carlospolopm[1;32m |
|
||
| [33mRespect on HTB[1;32m : [1;31mSirBroccoli [1;32m |
|
||
|---------------------------------------------------------------------------------|
|
||
| [34mThank you![1;32m |
|
||
\---------------------------------------------------------------------------------/
|
||
[0m
|