GIAC
GPEN · Question #480
A penetration tester used a client-side browser exploit from metasploit to get an unprivileged shell prompt on the target Windows desktop. The penetration tester then tried using the getsystem command
Sign in or unlock GPEN to reveal the answer and full explanation for question #480. The question stem and answer options stay visible for context.
Exploitation & Post-Exploitation Techniques
Question
A penetration tester used a client-side browser exploit from metasploit to get an unprivileged shell prompt on the target Windows desktop. The penetration tester then tried using the getsystem command to perform a local privilege escalation which failed. Which of the following could resolve the problem?
Options
- ALoad priv module and try getsystem again
- BRun getuid command, then getpriv command, and try getsystem again
- CRun getuid command and try getsystem again
- DUse getprivs command instead of getsystem
Unlock GPEN to see the answer
You've previewed enough free GPEN questions. Unlock GPEN for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Metasploit#privilege escalation#getsystem#Meterpreter