Login or register
SecDocs RSS feed

Paper details

Title Token Kidnapping's Revenge
Type Paper
Tags Windows exploiting
Abstract On April 14, 2009 Microsoft released a patch (documented here) to fix the issues detailed in my previous Token Kidnapping presentation (download PDF). The patch properly fixed the issues but... This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the brand new Windows 2008 R2 and Windows 7. These new attacks allow to bypass new Windows services protections such as Per service SID, Write restricted token, etc. It will be demonstrated that almost any process with impersonation rights can elevate privileges to Local System account and completely compromise Windows OSs. While the issues are not critical in nature since impersonation rights are required, they allow to exploit services such as IIS 6, IIS 7, SQL Server, etc. in some specific scenarios. Exploits code for those services will be released. The presentation will be given in a very practical way showing how the new issues were found, with what tools, techniques, etc. allowing the participants to learn how to easily find these kind security issues in Windows operating systems.
Authors Cesar Cerrudo
Submitted September 07, 2011
Rating
Currently 0/5 stars (0 votes).
Correlation
Linked to
Event Black Hat USA 2010
Resource ---
Download
Source BlackHat-USA-2010-Cerrudo-Toke-Kidnapping%27s-Revenge-wp.pdf
Size 168.1 KB
MD5 622b1073acb2c172d97853e61ce106b2
SHA1 3af7473ffc2d358e75f409f7d4e3ce65f63ab78c

Comments
No comments.
Add new Only logged in users can comment.


Click here to lend your support to: SecDocs and make a donation at www.pledgie.com !