Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

NT RASMAN Privilege Escalation Vulnerability

BertzHole.exe <binary pathname> will modify the RASMAN/ImagePath key in the Registry with the service executable to be run in its place. BertHole.exe (author supplied) is a sample trojan service that may be run. This executable runs a service which launches a netcat listener on tcp port 123. (nc -d -L -p 123 -e cmd.exe). (This service may or may not run with errors.)







 

Privacy Statement
Copyright 2009, SecurityFocus