|
NT RASMAN Privilege Escalation Vulnerability
BertzHole.exe <binary pathname> will modify the RASMAN/ImagePath key in the Registry with the service executable to be run in its place. BertHole.exe (author supplied) is a sample trojan service that may be run. This executable runs a service which launches a netcat listener on tcp port 123. (nc -d -L -p 123 -e cmd.exe). (This service may or may not run with errors.) |
|
|
Privacy Statement |