black hat大会之后代码公布了。

Source: https://media.blackhat.com/bh-us-10/source/Cerrudo/Source.zip

PDF:
[1] https://media.blackhat.com/bh-us-10/whitepapers/Cerrudo/BlackHat-USA-2010-Cerrudo-Toke-Kidnapping%27s-Revenge-wp.pdf
[2] https://media.blackhat.com/bh-us-10/presentations/Cerrudo/BlackHat-USA-2010-Cerrudo-Toke-Kidnapping%27s-Revenge-slides.pdf

This new presentation will detail new design mistakes and security issues that can be exploited to elevate privileges on all Windows versions including the brand new Windows 2008 R2 and Windows 7. These new attacks allow to bypass new Windows services protections such as Per service SID, Write restricted token, etc. It will be demonstrated that almost any process with impersonation rights can elevate privileges to Local System account and completely compromise Windows OSs. While the issues are not critical in nature since impersonation rights are required, they allow to exploit services such as IIS 6, IIS 7, SQL Server, etc. in some specific scenarios. Exploits code for those services will be released. The presentation will be given in a very practical way showing how the new issues were found, with what tools, techniques, etc. allowing the participants to learn how to easily find these kind security issues in Windows operating systems.

http://www.blackhat.com/html/bh-us-10/bh-us-10-archives.html

NP编译的:http://pcsec.googlecode.com/files/pr.rar

相关文章

本文还暂无回复

添加回复

支持 Ctrl+Enter 快速提交