Thủ Phủ Hacker Mũ Trắng Buôn Ma Thuột

Chương trình Đào tạo Hacker Mũ Trắng Việt Nam tại Thành phố Buôn Ma Thuột kết hợp du lịch. Khi đi là newbie - Khi về là HACKER MŨ TRẮNG !

Hacking Và Penetration Test Với Metasploit

Chương trình huấn luyện sử dụng Metasploit Framework để Tấn Công Thử Nghiệm hay Hacking của Security365.

Tài Liệu Computer Forensic Của C50

Tài liệu học tập về Truy Tìm Chứng Cứ Số (CHFI) do Security365 biên soạn phục vụ cho công tác đào tạo tại C50.

Sinh Viên Với Hacking Và Bảo Mật Thông Tin

Cuộc thi sinh viên cới Hacking. Với các thử thách tấn công trang web dành cho sinh viên trên nền Hackademic Challenge.

Tấn Công Và Phòng Thủ Với BackTrack / Kali Linux

Khóa học tấn công và phòng thủ với bộ công cụ chuyên nghiệp của các Hacker là BackTrack và Kali LINUX dựa trên nội dung Offensive Security

Sayfalar

Showing posts with label RunFromProcess. Show all posts
Showing posts with label RunFromProcess. Show all posts

RunFromProcess - Run a Windows program with a user of another process

RunFromProcess is a command-line utility that allows you to run a program from another process that you choose. 

The program that you run will be executed as a child of the specified process and it'll run with the same user and security context of the specified parent process.

Using RunFromProcess

RunFromProcess requires 2 command-line parameters: 
RunFromProcess.exe [Parent Process Name/ID] [Process To Run]

The first parameter is the process name (for example: myprocess.exe) or process ID of the parent process that will run the program you need. 

The second parameter is the full path filename of the program that you want to run. You can also specify command-line parameters for the specified program.

Optionally, you can specify 'nomsg' prefix before the 2 major parameters if you want that RunFromProcess won't display any error message.

Optionally, you can specify 'admin' prefix before all other parameters if you want to execute RunFromProcess as administrator.

Examples: 
RunFromProcess.exe 761 c:\temp\myprog.exe 
RunFromProcess.exe explorer.exe "c:\program files\abcd\mm.exe" 34 abc dd 
RunFromProcess.exe nomsg explorer.exe "c:\software\soft.exe" 
RunFromProcess.exe admin winlogon.exe "c:\software\soft.exe"

What you can do with this tool

Here's an example of what you can do with this tool: 

when you run a program from the schedule service of Windows, the program will run under a SYSTEM account, for example: 
at 18:00 c:\software\myprogram.exe

If you want to run the program with the current logged-on user, you can do it in this way: 
at 18:00 c:\software\RunFromProcess.exe nomsg explorer.exe c:\software\myprogram.exe

If you want to run a program with SYSTEM user, you can do it in this way: (The admin parameter is needed to get admin rights on Windows Vista/7/8 when UAC is turned on) 
RunFromProcess.exe admin winlogon.exe c:\windows\regedit.exe

If you execute the above command on Windows 7/Vista, RegEdit will be opened with a SYSTEM account, and you'll be able to see all secret Registry keys that are not available for any other user.