OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [Full-disclosure] Outpost Firewall vulnerability, users gaining system rights

From: H. Wiedemann (dprherr-der-mails.de)
Date: Sat Jul 22 2006 - 13:05:05 CDT


And an even more simple method in version 3.51.759.xxxx:

"Options - Application - Components - Edit List - Add"

This dialog doesn't have a disabled context menu, so just go to the
windows\system32 folder, right click on "cmd.exe" and choose "open".

More vulnerabilites to come unless Agnitum separates the service and the
GUI parts ;)

--

H. WIEDEMANN

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/