It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
A simple Windows hack is unfixed a year later A simple Windows hack is unfixed a year later
FAQ Members List Calendar Search Today's Posts Mark Forums Read


A simple Windows hack is unfixed a year later
Reply
 
Thread Tools
Old 19th October 2018, 09:48   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,578
Stefan Mileschin Freshly Registered
Default A simple Windows hack is unfixed a year later

All a hacker could want

A simple Windows security hack which was discovered a year ago is still unpatched.

Discovered by Sebastián Castro, a security researcher for CSL, the technique targets one of the parameters of Windows user accounts known as the Relative Identifier (RID).

It delivers the hacker admin rights and boot persistence on Windows PCs that's simple to execute and hard to stop.

For some reason, though, the flaw has not been patched and it has not received either media coverage. Fortunately, the hackers have not spotted it either, and it has not been part of any malware campaigns.

The RID is a code added at the end of account security identifiers (SIDs) that describes that user's permissions group. There are several RIDs available, but the most common ones are 501 for the standard guest account, and 500 for admin accounts.

Castro, with help from CSL CEO Pedro García, discovered that by tinkering with registry keys that store information about each Windows account, he could modify the RID associated with a specific account and grant it a different RID, for another account group.

A hacker cannot remotely infect a computer unless that computer has been left exposed on the Internet without a password.

But it helps when a hacker has a foothold on a system. The hacker can give admin permissions to a compromised low-level account and gain a permanent backdoor with full SYSTEM access on a Windows PC.

https://fudzilla.com/news/47415-a-si...d-a-year-later
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows 10 Buggy Updates? Our Patching Is Simple, Regular, Consistent Says Microsoft Stefan Mileschin WebNews 0 7th August 2018 10:27
Cortana can be used to hack Windows 10 PCs Stefan Mileschin WebNews 0 14th June 2018 11:44
House Democrats adopt encrypted messaging after last year's hack Stefan Mileschin WebNews 0 21st July 2017 06:51
Russians exploit Windows hack Stefan Mileschin WebNews 0 3rd November 2016 11:54
Congressional leaders were briefed on DNC hack last year Stefan Mileschin WebNews 0 15th August 2016 15:05
Facebook likes 10 year old’s bug hack Stefan Mileschin WebNews 0 6th May 2016 06:08
Keyless entry systems are still vulnerable to simple hack Stefan Mileschin WebNews 0 27th March 2016 09:29
FBI warned of a Sony-style hack in a report last year Stefan Mileschin WebNews 0 26th December 2014 12:28
Dangerous IE 8 exploit remains unfixed by Microsoft, instead users are urged to upgra Stefan Mileschin WebNews 0 7th May 2013 08:13
Windows RT jailbreak automates a complex hack Stefan Mileschin WebNews 0 14th January 2013 09:09

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 19:58.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO