Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email email@example.com
RE: [Full-Disclosure] XP Remote Desktop Remote Activation
From: Dominick Baier (seclistsleastprivilege.com)
Date: Sat Oct 02 2004 - 10:43:11 CDT
if you have an administrator password for the machine you can just use WMIC
to turn remote desktop on.
wmic /NODE:Server /USER:administrator RDTOGGLE WHERE ServerName="Server"
CALL SetAllowTSConnections 1
[mailto:full-disclosure-adminlists.netsys.com] On Behalf Of Fixer
Sent: Samstag, 2. Oktober 2004 06:51
Subject: [Full-Disclosure] XP Remote Desktop Remote Activation
XP Remote Desktop Remote Activation
Windows XP Professional provides a service called Remote Desktop, which
allows a user to remotely control the desktop as if he or she were in front
of the system locally (ala VNC, pcAnywhere, etc.).
By default, Remote Desktop is shipped with this service turned off and only
the Administrator is allowed access to this service. It is possible,
however, to modify a series of registry keys that may allow a malicious user
who has already gained a command shell to activate Remote Desktop and add a
user they have created for themselves as well as to hide that user so that
it will not show up as a user in the Remote Desktop user list. The
instructions for this are attached.
Additionally, I have listed a sample .reg file of the type that is discussed
in the instructions below.
To the Frozen Chozen...On-On (www.frozen-chozen-h3.org)
On to the exploit.... Fixer
.reg file (remember, the xx xx are the values you need to change)
Windows Registry Editor Version 5.00
(obviously change "lus3r" to the name of the account you created)
Full-Disclosure - We believe in it.