You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

借助备份还原权限模拟访问令牌跨域复制文件的技术问询

Alright, let's walk through how you can use your Backup & Restore privileges across the trusted domains to copy files via token impersonation. Since you hold both Account A (with backup/restore on Computer A) and Account B (with backup/restore on Computer B), here's a practical, step-by-step breakdown:

Core Background

First, a quick recap on why this works:

  • The SeBackupPrivilege lets you read any file on the local machine, bypassing standard ACL permissions—this is designed for legitimate backup operations, but we can leverage it to access files you wouldn't normally have rights to.
  • The SeRestorePrivilege lets you write any file to the local machine, also bypassing ACLs.
  • The cross-domain trust allows you to authenticate with either account on the other domain's computers, which is key for moving files between them.
Step-by-Step: Copying from Computer A to Computer B

Let's say you want to move files from Computer A (Domain A) to Computer B (Domain B):

1. Prepare the Source Files on Computer A (Using Account A)

Log into Computer A with Account A, then open an elevated PowerShell or Command Prompt:

  • First, verify and enable the SeBackupPrivilege:
    # Check current privileges
    whoami /priv
    
    # Enable SeBackupPrivilege if it's disabled
    $currentId = [System.Security.Principal.WindowsIdentity]::GetCurrent()
    $backupPriv = $currentId.Privileges | Where-Object { $_.PrivilegeName -eq 'SeBackupPrivilege' }
    if ($backupPriv -and !$backupPriv.Enabled) {
        $backupPriv.Enabled = $true
    }
    
  • Use robocopy in backup mode to copy the source files to a temporary location (either local or a shared folder accessible to Account B):
    # Copy entire directory with backup mode (bypasses ACLs for reading)
    robocopy "C:\Path\To\Source\Files" "C:\Temp\CrossDomainBackup" /B /E /COPYALL
    
    The /B flag triggers backup mode, /E copies subdirectories, and /COPYALL preserves all file attributes.

2. Transfer to Computer B (Using Account B)

Now you need to move the backed-up files to Computer B using Account B's restore privileges:

  • Open a new elevated Command Prompt/PowerShell as Account B (cross-domain):
    runas /user:DomainB\AccountB "powershell.exe"
    
    Enter Account B's password when prompted.
  • In this new session, enable SeRestorePrivilege:
    whoami /priv
    
    $currentId = [System.Security.Principal.WindowsIdentity]::GetCurrent()
    $restorePriv = $currentId.Privileges | Where-Object { $_.PrivilegeName -eq 'SeRestorePrivilege' }
    if ($restorePriv -and !$restorePriv.Enabled) {
        $restorePriv.Enabled = $true
    }
    
  • Copy the backed-up files to Computer B's target location using restore mode:
    # Replace the source path with your temp backup location (could be \\ComputerA\Temp\CrossDomainBackup if shared)
    robocopy "C:\Temp\CrossDomainBackup" "D:\Target\Path\On\ComputerB" /B /E /COPYALL
    
    The /B flag here uses restore mode to bypass target ACLs, letting you write files even if Account B wouldn't normally have permission (though in this case, Account B is an admin, but the privilege ensures you can overwrite any protected files).
Reverse Direction (Computer B to Computer A)

The process is identical—just swap Account A/Computer A with Account B/Computer B:

  1. Log into Computer B with Account B, enable SeBackupPrivilege, and backup files to a shared/temp location.
  2. Run a session as Account A on Computer A, enable SeRestorePrivilege, and restore the files to your target path.
Advanced: Direct Cross-Network Copy (No Temp Folder)

If you don't want to use a temp folder, you can combine token impersonation with backup/restore privileges directly over the network:

  • On Computer A (Account A), enable SeBackupPrivilege.
  • Use psexec to run a robocopy command as Account B on Computer B, pulling files from Computer A:
    psexec \\ComputerB -u DomainB\AccountB -p "AccountBPassword" robocopy "\\ComputerA\Path\To\Source" "D:\Target\On\ComputerB" /B /E /COPYALL
    
    This works because:
    • The robocopy command runs on Computer B as Account B, so SeRestorePrivilege applies for writing.
    • The source path is accessed via Computer A, where Account A's SeBackupPrivilege allows reading the files (even if Account B wouldn't normally have access to them).
Key Notes
  • Always ensure you're running commands in an elevated (admin) session—privileges like SeBackup/SeRestore require admin rights to enable.
  • The cross-domain trust must allow both accounts to authenticate on the opposite domain's computers (which your scenario states is already configured).
  • If you're working with sensitive files, make sure the temp/shared folder is secured to prevent unauthorized access.

内容的提问来源于stack exchange,提问作者C Sharp Conner

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 10:38:30