OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] Microsoft Windows keybd_event validation vulnerability

From: Jerome Athias (jerome.athiasfree.fr)
Date: Tue Sep 06 2005 - 06:20:37 CDT


It was posted by Andres Tarasco to full-disclosure allready

Additionaly:

1) french version of the advisory:
 http://www.athias.fr/alertes-bulletins-securite/20050905_Microsoft.Windows_Validation.keybd_event.html

2) I use to use this trick to obtain SYSTEM privileges with just ADMIN
privileges:

AT 20:00 /INTERACTIVE cmd.exe

Cheers,
/JA

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/