借助备份还原权限模拟访问令牌跨域复制文件的技术问询
Alright, let's walk through how you can use your Backup & Restore privileges across the trusted domains to copy files via token impersonation. Since you hold both Account A (with backup/restore on Computer A) and Account B (with backup/restore on Computer B), here's a practical, step-by-step breakdown:
First, a quick recap on why this works:
- The
SeBackupPrivilegelets you read any file on the local machine, bypassing standard ACL permissions—this is designed for legitimate backup operations, but we can leverage it to access files you wouldn't normally have rights to. - The
SeRestorePrivilegelets you write any file to the local machine, also bypassing ACLs. - The cross-domain trust allows you to authenticate with either account on the other domain's computers, which is key for moving files between them.
Let's say you want to move files from Computer A (Domain A) to Computer B (Domain B):
1. Prepare the Source Files on Computer A (Using Account A)
Log into Computer A with Account A, then open an elevated PowerShell or Command Prompt:
- First, verify and enable the
SeBackupPrivilege:# Check current privileges whoami /priv # Enable SeBackupPrivilege if it's disabled $currentId = [System.Security.Principal.WindowsIdentity]::GetCurrent() $backupPriv = $currentId.Privileges | Where-Object { $_.PrivilegeName -eq 'SeBackupPrivilege' } if ($backupPriv -and !$backupPriv.Enabled) { $backupPriv.Enabled = $true } - Use
robocopyin backup mode to copy the source files to a temporary location (either local or a shared folder accessible to Account B):
The# Copy entire directory with backup mode (bypasses ACLs for reading) robocopy "C:\Path\To\Source\Files" "C:\Temp\CrossDomainBackup" /B /E /COPYALL/Bflag triggers backup mode,/Ecopies subdirectories, and/COPYALLpreserves all file attributes.
2. Transfer to Computer B (Using Account B)
Now you need to move the backed-up files to Computer B using Account B's restore privileges:
- Open a new elevated Command Prompt/PowerShell as Account B (cross-domain):
Enter Account B's password when prompted.runas /user:DomainB\AccountB "powershell.exe" - In this new session, enable
SeRestorePrivilege:whoami /priv $currentId = [System.Security.Principal.WindowsIdentity]::GetCurrent() $restorePriv = $currentId.Privileges | Where-Object { $_.PrivilegeName -eq 'SeRestorePrivilege' } if ($restorePriv -and !$restorePriv.Enabled) { $restorePriv.Enabled = $true } - Copy the backed-up files to Computer B's target location using restore mode:
The# Replace the source path with your temp backup location (could be \\ComputerA\Temp\CrossDomainBackup if shared) robocopy "C:\Temp\CrossDomainBackup" "D:\Target\Path\On\ComputerB" /B /E /COPYALL/Bflag here uses restore mode to bypass target ACLs, letting you write files even if Account B wouldn't normally have permission (though in this case, Account B is an admin, but the privilege ensures you can overwrite any protected files).
The process is identical—just swap Account A/Computer A with Account B/Computer B:
- Log into Computer B with Account B, enable
SeBackupPrivilege, and backup files to a shared/temp location. - Run a session as Account A on Computer A, enable
SeRestorePrivilege, and restore the files to your target path.
If you don't want to use a temp folder, you can combine token impersonation with backup/restore privileges directly over the network:
- On Computer A (Account A), enable
SeBackupPrivilege. - Use
psexecto run a robocopy command as Account B on Computer B, pulling files from Computer A:
This works because:psexec \\ComputerB -u DomainB\AccountB -p "AccountBPassword" robocopy "\\ComputerA\Path\To\Source" "D:\Target\On\ComputerB" /B /E /COPYALL- The robocopy command runs on Computer B as Account B, so
SeRestorePrivilegeapplies for writing. - The source path is accessed via Computer A, where Account A's
SeBackupPrivilegeallows reading the files (even if Account B wouldn't normally have access to them).
- The robocopy command runs on Computer B as Account B, so
- Always ensure you're running commands in an elevated (admin) session—privileges like SeBackup/SeRestore require admin rights to enable.
- The cross-domain trust must allow both accounts to authenticate on the opposite domain's computers (which your scenario states is already configured).
- If you're working with sensitive files, make sure the temp/shared folder is secured to prevent unauthorized access.
内容的提问来源于stack exchange,提问作者C Sharp Conner

