Win 2k/NT Security Hole

General Network security, firewalls, port filtering/forwarding, wireless security, anti-spyware, as well as spam control and privacy discussions.
Post Reply
DesertFox
Member
Posts: 22
Joined: Thu Nov 01, 2001 6:28 pm
Location: In a far, far away place where Apple and AOL are just a bad dream.

Win 2k/NT Security Hole

Post by DesertFox »

Hey, I was just out reading news, and came across this:

http://www.extremetech.com/article/0,3396,s=201&a=24754,00.asp


Thought i would give you the heads up if you find that interesting.
User avatar
greEd
Posts: 807
Joined: Wed May 09, 2001 12:00 am
Location: Maryland

Post by greEd »

Yes I heard about this earlier today ... I haven't done much with it yet but it looks interesting. Code has also been released for the exploit, I upped it to my server if you want to check it out:

http://www.computerglitch.net/node.php?id=3 "debploit" under Misc. Security.

To test your system for this vulnerability:


1. Download DebPloit.zip and unzip it to the directory on your hard drive.


2. Logoff and login again using Guest (or any other non-administrative
account) account.


3. Run ERunAsX.exe from the command line and specify a program you wish to
execute under the SYSTEM account (e.g. "ERunAsX.exe cmd").


4. Your program now runs under the SYSTEM account and you can do everything
(e.g. create new user with an administrative privileges) on the local
computer.

regards,
greEd
"I'm doing a (free) operating system (just a hobby, won't be big and professional...) for AT clones... It's not portable and it probably [won't ever] support anything other than AT hard disks, as thats all I have :-(." --Posted on Usenet August 1991 by Linus Trovalds
http://www.computerglitch.net
curiosity builds security | dd if=/dev/zero of=/dev/hda bs=512 count=100
EOF
User avatar
JackHamma96
Regular Member
Posts: 202
Joined: Mon Mar 11, 2002 5:10 pm
Location: North Carolina

Post by JackHamma96 »

I always knew that but I thought I had configured Win2k wrong :rolleyes:
Post Reply