Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-disclosure] Windows Access Control Demystified. |
|---|---|
| Date: | Tue, 31 Jan 2006 16:33:46 -0500 (EST) |
Hello everybody,
We have constructed a logical model of Windows XP access control, in a declarative but executable (Datalog) format. We have built a scanner that reads access-control configuration information from the Windows registry, file system, and service control manager database, and feeds raw configuration data to the model. Therefore we can reason about such things as the existence of privilege-escalation attacks, and indeed we have found several user-to-administrator vulnerabilities caused by misconfigurations of the access-control lists of commercial software from several major vendors. We propose tools such as ours as a vehicle for software developers and system administrators to model and debug the complex interactions of access control on installations under Windows.
The full version of the paper can be found at:
http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf
regards, Sudhakar Govindavajhala and Andrew Appel.
Bio:
Sudhakar Govindavajhala Department of Computer Science Graduate Student, Princeton University Ph : +1 609 258 1763 http://www.cs.princeton.edu/~sudhakar _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [Full-disclosure] [SECURITY] [DSA 960-2] New libmail-audit-perl packages fix insecure temporary file use, Martin Schulze |
|---|---|
| Next by Date: | Re: [Full-disclosure] I stole code, Steve Kudlak |
| Previous by Thread: | [Full-disclosure] [SECURITY] [DSA 960-2] New libmail-audit-perl packages fix insecure temporary file use, Martin Schulze |
| Next by Thread: | [Full-disclosure] ZRCSA-200601: SPIP - Multiple Vulnerabilities, Siegfried |
| Indexes: | [Date] [Thread] [Top] [All Lists] |