Madshrimps Forum Madness

Madshrimps Forum Madness (https://www.madshrimps.be/vbulletin/)
-   WebNews (https://www.madshrimps.be/vbulletin/f22/)
-   -   A simple Windows hack is unfixed a year later (https://www.madshrimps.be/vbulletin/f22/simple-windows-hack-unfixed-year-later-181704/)

Stefan Mileschin 19th October 2018 09:48

A simple Windows hack is unfixed a year later
 
All a hacker could want

A simple Windows security hack which was discovered a year ago is still unpatched.

Discovered by Sebastián Castro, a security researcher for CSL, the technique targets one of the parameters of Windows user accounts known as the Relative Identifier (RID).

It delivers the hacker admin rights and boot persistence on Windows PCs that's simple to execute and hard to stop.

For some reason, though, the flaw has not been patched and it has not received either media coverage. Fortunately, the hackers have not spotted it either, and it has not been part of any malware campaigns.

The RID is a code added at the end of account security identifiers (SIDs) that describes that user's permissions group. There are several RIDs available, but the most common ones are 501 for the standard guest account, and 500 for admin accounts.

Castro, with help from CSL CEO Pedro García, discovered that by tinkering with registry keys that store information about each Windows account, he could modify the RID associated with a specific account and grant it a different RID, for another account group.

A hacker cannot remotely infect a computer unless that computer has been left exposed on the Internet without a password.

But it helps when a hacker has a foothold on a system. The hacker can give admin permissions to a compromised low-level account and gain a permanent backdoor with full SYSTEM access on a Windows PC.

https://fudzilla.com/news/47415-a-si...d-a-year-later


All times are GMT +1. The time now is 18:13.

Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO