screen saver privilege

screen saver privilege

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
screen saver privilege LoneWolf210 04-16-2007
Posted by on April 16, 2007, 11:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I'm sure that most of you have heard of the privilege escalation
technique of replacing logon.scr with cmd. well I was playing around
on the computer and decided to install cmd as an option for a user
screen saver. However when the prompt was not run with system rights
as when it is when it replaces logon.scr. I was wondering if anyone
knew why this was?


Posted by Sebastian G on April 17, 2007, 1:15 am
If you were  Registered and logged in, you could reply and use other advanced thread options
LoneWolf210@gmail.com wrote:

> I'm sure that most of you have heard of the privilege escalation
> technique of replacing logon.scr with cmd.


We've heard a lot about it, but this still doesn't make it a privilege
escalation. To replace logon.scr, you already need to have admin rights.

> However when the prompt was not run with system rights
> as when it is when it replaces logon.scr.


Of course not, it is run with the rights of the user.

> I was wondering if anyone knew why this was?


WinLogon uses Impersonation to execute the CreateProcess() call with the
credentials of the user. On Windows Server 2003 and later, it uses
CreateProcessAsUser().

Similar ThreadsPosted
Screen saver timeout changed to 180 minutes and doesn't activate March 28, 2005, 7:57 pm
Getting rid of malware screen theme July 30, 2005, 6:01 pm
Small Screen Security site September 14, 2006, 6:16 am
SSRT4699 HP-UX SAM local privilege increase December 24, 2004, 12:47 pm
SSRT4699 rev.2 HP-UX SAM local privilege increase February 3, 2005, 4:55 pm
SSRT4699 rev.1 HP-UX SAM local privilege increase January 14, 2005, 12:50 pm
SSRT4687 rev.0 HP-UX newgrp(1) local privilege elevation December 20, 2004, 12:55 pm
HPSBUX02091 SSRT061099 rev.1 - HP-UX Local Increased Privilege January 24, 2006, 2:26 pm
HPSBUX02091 SSRT061099 rev.2 - HP-UX Local Increased Privilege November 1, 2006, 2:23 pm
SSRT051004 rev.0 - HP-UX Java Runtime Environment (JRE) Untrusted Applet Elevates Privilege August 30, 2005, 9:42 pm

The site map in XML format XML site map

Contact Us | Privacy Policy