BugTraq
Re: Get admin rights using Doro (pdf creator) Jan 19 2004 02:43PM
the_sz gmx co uk
In-Reply-To: <7814219078.20031214220641 (at) portsonline (dot) net [email concealed]>

I'm the author of Doro. Version 1.15 fixes this problem.

run.to/sz

>Received: (qmail 2135 invoked from network); 15 Dec 2003 20:22:15 -0000

>Received: from outgoing2.securityfocus.com (205.206.231.26)

> by mail.securityfocus.com with SMTP; 15 Dec 2003 20:22:15 -0000

>Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20])

> by outgoing2.securityfocus.com (Postfix) with QMQP

> id 0FDF48FCEE; Mon, 15 Dec 2003 07:27:49 -0700 (MST)

>Mailing-List: contact bugtraq-help (at) securityfocus (dot) com [email concealed]; run by ezmlm

>Precedence: bulk

>List-Id: <bugtraq.list-id.securityfocus.com>

>List-Post: <mailto:bugtraq (at) securityfocus (dot) com [email concealed]>

>List-Help: <mailto:bugtraq-help (at) securityfocus (dot) com [email concealed]>

>List-Unsubscribe: <mailto:bugtraq-unsubscribe (at) securityfocus (dot) com [email concealed]>

>List-Subscribe: <mailto:bugtraq-subscribe (at) securityfocus (dot) com [email concealed]>

>Delivered-To: mailing list bugtraq (at) securityfocus (dot) com [email concealed]

>Delivered-To: moderator for bugtraq (at) securityfocus (dot) com [email concealed]

>Received: (qmail 13164 invoked from network); 14 Dec 2003 21:02:05 -0000

>Date: Sun, 14 Dec 2003 22:06:41 +0100

>From: Ramon Kukla <ml (at) portsonline (dot) net [email concealed]>

>X-Mailer: The Bat! (v2.01.3) Personal

>Reply-To: Ramon Kukla <ml (at) portsonline (dot) net [email concealed]>

>X-Priority: 3 (Normal)

>Message-ID: <7814219078.20031214220641 (at) portsonline (dot) net [email concealed]>

>To: bugtraq (at) securityfocus (dot) com [email concealed]

>Subject: Get admin rights using Doro (pdf creator)

>MIME-Version: 1.0

>Content-Type: text/plain; charset=us-ascii

>Content-Transfer-Encoding: 7bit

>

>Hi,

>

>a few days ago i discovered a bug in Doro[1]. Doro is a free tool to

>create pdf files from any windows program. After installing Doro you

>have a new printer called 'Doro PDF Writer'.

>If you select 'Print' the spooler calls the printer filter 'doro.dll'.

>The 'doro.dll' then starts 'doro.exe' and a file requester appears.

>

>I guess that most of you see the problem. The spooler is controlled by

>the account 'system'. Therefore the file requester has the same rights.

>

>It's easy now to create a new user and move them into the group

>'admins'.

>

>I informed the coder of the software and he approved the problem.

>

>

>regards

>Ramon

>

>[1] http://www.geocities.com/the_real_sz/misc/doro.htm

>

>

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus