Skip to content
This repository has been archived by the owner on Jan 29, 2020. It is now read-only.

Bypass UAC via SluiFileHandlerHijack #1248

Open
wants to merge 3 commits into
base: dev
Choose a base branch
from

Conversation

ThePirateWhoSmellsOfSunflowers
Copy link
Contributor

@ThePirateWhoSmellsOfSunflowers ThePirateWhoSmellsOfSunflowers commented Oct 8, 2018

Hi all,

This module exploits the UAC Bypass via SluiFileHandlerHijack by @gushmazuko
Original bypass by @bytecode77

This is a rewriting (and supersede) of #1243 by @Truneski

Tested on W10 (if someone can test on W8)

🌻

@ThePirateWhoSmellsOfSunflowers
Copy link
Contributor Author

Currently, the module does not work on W8.1. The launcher is ok, Invoke-SluiBypass -command "powershellcmd is ok, but if you try Invoke-SluiBypass -command "powershell -NoP -NonI -w Hidden -enc [...] an error is raised:

This file does not have a program associated with it for performing this action. Please install a program or, if one is already installed, create an association in the Default Programs control panel.

Need time to debug before merging

@mr64bit mr64bit added the onhold Waiting for input/feedback from the user label Nov 28, 2018
@gushmazuko
Copy link

Good job!

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
onhold Waiting for input/feedback from the user
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants