Backup Operators
Last updated
Last updated
Membership of this group grants its members the SeBackup
and SeRestore
privileges. The SeBackupPrivilege
allows us to traverse any folder and list the folder contents. This will let us copy a file from a folder, even if there is no access control entry (ACE) for us in the folder's access control list (ACL). However, we can't do this using the standard copy command. Instead, we need to programmatically copy the data, making sure to specify the FILE_FLAG_BACKUP_SEMANTICS flag.
We can use this PoC to exploit the SeBackupPrivilege
, and copy forbidden files.
SeBackupPrivilege