OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] Question for the Windows pros

From: Paul Schmehl (paulsutdallas.edu)
Date: Thu Jan 19 2006 - 10:28:52 CST


--On Thursday, January 19, 2006 10:32:44 +0100 Nicolas RUFF
<nicolas.ruffgmail.com> wrote:
>
> The ImpersonateNamedPipeClient() risks have been fully documented by
> Blake Watts back in 2002.
> http://www.blakewatts.com/namedpipepaper.html
>
Does the Impersonate a client after authentication privilege grant the
account access to ImpersonateNamedPipeClient?

Paul Schmehl (paulsutdallas.edu)
Adjunct Information Security Officer
University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/ir/security/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/