Focus on Microsoft
Help with Exploit Feb 02 2007 07:25PM
Vic Brown (vabrown mailer fsu edu) (3 replies)
RE: Help with Exploit Feb 05 2007 04:30AM
Murda Mcloud (murdamcloud bigpond com)
RE: Help with Exploit Feb 04 2007 10:52PM
Murda Mcloud (murdamcloud bigpond com) (1 replies)
Re: Help with Exploit Apr 17 2007 10:11AM
Nicolas RUFF (nicolas ruff gmail com) (1 replies)
Re: Help with Exploit Apr 17 2007 01:39PM
Harlan Carvey (keydet89 yahoo com) (2 replies)
Re: Help with Exploit Apr 17 2007 09:47PM
Nicolas RUFF (nicolas ruff gmail com)
RE: Help with Exploit Apr 17 2007 03:29PM
James D. Stallard (james leafgrove com) (2 replies)
RE: Help with Exploit Apr 17 2007 10:46PM
Murda Mcloud (murdamcloud bigpond com)
RE: Help with Exploit Apr 17 2007 05:31PM
Miha Pihler (Miha Pihler snt si)
Hi,

You can also use psexec from
http://www.microsoft.com/technet/sysinternals/utilities/psexec.mspx to do
this...

psexec -i -d -s c:\windows\regedit.exe
(Run Regedit interactively in the System account to view the contents of the
SAM and SECURITY keys)

Vista will not allow you to run "at" with "/interactive"...

Miha

-----Original Message-----
From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]] On
Behalf Of James D. Stallard
Sent: Tuesday, April 17, 2007 5:30 PM
To: 'Harlan Carvey'; 'Nicolas RUFF'; 'Murda Mcloud'; 'Vic Brown'
Cc: focus-ms (at) securityfocus (dot) com [email concealed]
Subject: RE: Help with Exploit

Harlan, et al

To access the security regkeys in HKLM you don't need to change the ACLs.

This is an age-old (well, since early NT4 anyway) trick to get LOCALSYSTEM
privs on anything that allows you to run an AT job:

. Get the current time.
. From CMD line run "AT <time+1 minute> /interactive CMD.EXE".
. Wait for a minute.
. CMD window opens in LOCALSYSTEM context.
. Run REGEDIT from new CMD window.
. Navigate to HKLM\SECURITY.
. Marvel at now visible security keys: Cache, Policy, RXACT, SAM.

This particular trick is the basis for a deal of trivial priv escalation
attacks on windows, so if you can, you should secure the Task Scheduler with
a non-priv'ed user or disable it. Another good reason for not giving users
local admin rights.

Cheers

James

James D. Stallard, MIoD
Microsoft and Networks Infrastructure Technical Architect
Web: www.leafgrove.com
LinkedIn: www.linkedin.com/in/jamesdstallard
Skype: JamesDStallard

-----Original Message-----
From: listbounce (at) securityfocus (dot) com [email concealed] [mailto:listbounce (at) securityfocus (dot) com [email concealed]] On
Behalf Of Harlan Carvey
Sent: 17 April 2007 14:40
To: Nicolas RUFF; Murda Mcloud; 'Vic Brown'
Cc: focus-ms (at) securityfocus (dot) com [email concealed]
Subject: Re: Help with Exploit

> > I've done some googling and am finding that the
> new RR version checks the
> > security hive(which I believe to be 'invisible' to
> regedit-can someone
> > correct me if I'm wrong?).

On a live system, the Security hive is not accessible by default. You need
to change the ACLs so that the Admin has the ability to read the hive.

> I know I am coming late on this one, but registry keys that contain
> NULL characters cannot be accessed through REGEDIT. You have to rely
> on the low-level NTDLL API to access them. It is known "copy
> protection" trick :)

What?

------------------------------------------
Harlan Carvey, CISSP
author: "Windows Forensic Analysis"
http://windowsir.blogspot.com
------------------------------------------

0? *?H?÷
 ?0?1 0 +0? *?H?÷
 ? Æ0?=0?¦ͺVðßä¼Tþ"¬³rªU0
 *?H?÷
0_1 0 UUS10U
VeriSign, Inc.1705U .Class 1 Public Primary Certification Authority0
960129000000Z
280801235959Z0_1 0 UUS10U
VeriSign, Inc.1705U .Class 1 Public Primary Certification Authority0?0
 *?H?÷
0?å¿m£Va-?HqögÞ¹ë·???
?ú8%¯F??ås¨ ?$]
Ìen °ÐV????¡sß´X9knÁöÕ¨¨?ª1¬°4׏4g? ÍâNEVix?ÚÜG?)»6Éc\Åà×-?{¡·2°{0º*/1ªî£gÚÛ0
 *?H?÷
L?¸?ÆhßîC3]é¦Ë?Mz3ÿ?ô6­Ø?"6hl|BÌó?.Ä?°Oÿ?vùâ¼JéÍ ?
÷Å)ñ?"]¸±Ý#£{%F0yøêK?ÂÈã·ô@<Ã_SèHä?´{¡5°{%º¸Ó?«?84?óÑq?0?b0?
Ë  Ú Á???« tz´Î.30
 *?H?÷
0_1 0 UUS10U
VeriSign, Inc.1705U .Class 1 Public Primary Certification Authority0
980512000000Z
080512235959Z0Ì10U
VeriSign, Inc.10U VeriSign Trust Network1F0DU =www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated0?0
 *?H?÷
0?»ZD?»Uýz?-?Ox6¸
J²o?T¿¼èw*¹ðh»?Ù1ApzK¹HV-Çá?B«À¢?«D\ªBð?é/ûÂ;»¾É'
]¶°6B3µnT?O?J¿Úùè?¶ãÌÆ??j$?ãüàeº§±~ïÉÛ7jÈJÈ ä?£°0­0U0ÿ0GU @0>0< `?H?øE0-0++www.verisign.com/repository/RPA01U
*0(0& $ "? http://crl.verisign.com/pca1.crl0 U0 `?H?øB0
 *?H?÷
}?oEK8 ¸ÞéSd!¼äL+þ?@¬Ø
9j¡2!,?«YþÒb}U8°7sÜôfcb½áSpR?ç¨ØRé[-ªáÞϬ1TÔ?ÈØ#¨ï+2},È|?¨.wòDÑe
MtµîÓ?st.?;5rç@1?ӲīçV¾?ãû0?0?? 4L!hh??tÎèÉ].¶(0
 *?H?÷
0Ì10U
VeriSign, Inc.10U VeriSign Trust Network1F0DU =www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated0
070111000000Z
080111235959Z0?10U
VeriSign, Inc.10U VeriSign Trust Network1F0DU =www.verisign.com/repository/RPA Incorp. by Ref.,LIAB.LTD(c)9810U Persona Not Validated1402U +Digital ID Class 1 - Microsoft Full Service10U Miha Pihler1!0 *?H?÷
 miha.pihler (at) snt (dot) si0 [email concealed]?0
 *?H?÷
0?ïÐÒ Æ?ÁàäÚáLýÃÕî@6æI·<ÀýK&Þ?ébñ$«´???[?cs£K¦ÂKØÀeµ)£sÂjü

Í5XÝî "ã9ñèø°ß?C%³&à×?(èx4±Ô?#ÿ¥ìÃNÏõq??ï¤\®ª\¿z¹|Íiù£µ0²0 U00DU =0;09 `?H?øE0*0(+https://www.verisign.com/rpa0 U
 0U%0++03U,0*0( & $?"http://crl.verisig
n.com/class1.crl0
 *?H?÷
8§1¡íÚVgðT'îø¦ÉÁÆbLd?¥?j¢v9ç QRv§ù!À`F]Xã@-{Ä«Aøæ
5Ϥc8Vý¡ÚÒЫuÛ®þÆWîôÏ~Ü:®?ÝÒ^r?º?1üø{ôÿÇ??q¹?®į,j¹G0â?®^â«å?
1?0??0á0Ì10U
VeriSign, Inc.10U VeriSign Trust Network1F0DU =www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated4L!hh??tÎèÉ].¶(0 + ?0 *?H?÷
 1  *?H?÷
0 *?H?÷
 1
070417173115Z0# *?H?÷
 1±?xÚ&ç0ãL(¡-×ÇÕFÖ¨ñ0· *?H?÷
 1©0¦0  `?He*0  `?He0
*?H?÷
0  `?He0*?H?÷
?0
*?H?÷
@0+0
*?H?÷
(0+0  `?He0  `?He0  `?He0
*?H?÷
0ò +?71ä0á0Ì10U
VeriSign, Inc.10U VeriSign Trust Network1F0DU =www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated4L!hh??tÎèÉ].¶(0ô *?H?÷
  1ä á0Ì10U
VeriSign, Inc.10U VeriSign Trust Network1F0DU =www.verisign.com/repository/RPA Incorp. By Ref.,LIAB.LTD(c)981H0FU?VeriSign Class 1 CA Individual Subscriber-Persona Not Validated4L!hh??tÎèÉ].¶(0
 *?H?÷
?#U!zoå?ÝüöjbßD]jZõõt·û"pF>Øz%ÿnèúl(?¹J? þwFyõÖã­û?-<è\ð
ßYL¦P"?¨¹8U³Èk<MBJ¤Á¬ý>lÐ!¸EKó§LR³®Ë7p
´/??¨®h±°|kÀbÙ?mÉK?á

[ reply ]
Re: Help with Exploit Feb 02 2007 09:18PM
Josh Miller (joshua itsecureadmin com)


 

Privacy Statement
Copyright 2010, SecurityFocus