Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation |
|---|---|
| Date: | Sun, 28 Nov 2004 01:34:08 +0100 (CET) |
On Thu, 25 Nov 2004, 3APA3A wrote:
Power Users can install software, so they can replace any file in SYSTEM32 directory, including screensaver. It allows to trojan any system file (for example, one can replace winspool.exe with cmd.exe to obtain SYSTEM permissions). It's by design and it's documented. Just never assign users in Power Users group, as Microsoft recommends you. I see no security vulnerability here.
They have two different groups of users: more or less almighty Administrators and Power Users who are supposed to be less powerful. But Power Users are in fact as powerful as Administrators. This leads to a false sense of security and this is a vulnerability...even if it might not be a vulnerability in the technical sense. Why don't they remove the group or disable it when users should not be assigned to it? Moreover, it is pretty stupid to give users rights to modify critical system directories just to let them install new software. --Pavel Kankovsky aka Peak [ Boycott Microsoft--http://www.vcnet.com/bms ] "Resistance is futile. Open your source code and prepare for assimilation." _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: [Full-Disclosure] FIREFOX flaws: nested array sort() loop Stack overflow exception, Heikki Toivonen |
|---|---|
| Next by Date: | Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation, devis |
| Previous by Thread: | Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation, David Vincent |
| Next by Thread: | Re: [Full-Disclosure] MS Windows Screensaver Privilege Escalation, devis |
| Indexes: | [Date] [Thread] [Top] [All Lists] |