所有的悲伤,总会留下一丝欢乐的线索; 所有的遗憾,总会留下一处完美的角落。 我在冰封的深海,寻找希望的缺口; 却在午夜惊醒时,蓦然瞥见夜空绝美的月光绝唱.......

Pages: 1/1 First page 1 Final page [ View by Articles | List ]

MS Windows 2003 Token Kidnapping Local Exploit PoC

  [阴 October 9, 2008 12:40 | by !4p47hy ]
It has been a long time since Token Kidnapping presentation (http://www.argeniss.com/research/TokenKidnapping.pdf)
was published so I decided to release a PoC exploit for Win2k3 that alows to execute code under SYSTEM account.

Basically if you can run code under any service in Win2k3 then you can own Windows, this is because Windows services accounts can impersonate.  Other process (not services) that can impersonate are IIS 6 worker processes so if you can run code from an ASP .NET or classic ASP web application then you can own Windows too. If you provide shared hosting services then I would recomend to not allow users to run this kind of code from ASP.
Pages: 1/1 First page 1 Final page [ View by Articles | List ]