Privilege escalation from restricted to localsystem on xp sp2. Possible??

Тема в разделе "WASM.ENGLISH", создана пользователем Gurgo, 14 янв 2006.

  1. Gurgo

    Gurgo New Member

    Публикаций:
    0
    Регистрация:
    14 янв 2006
    Сообщения:
    1
    The question is given.

    Are there any chance for a restricted/limited user to gain localsystem rights on an WinXP SP2?

    Is Code injecting/executing possible to/from LocalSystem processes?



    Code injection works fine with SetWindowText() but how to execute it?

    Satck/heap based overlflows could be used?



    Is it possible to start an application with localsystem rights by restricted user?



    Thank you for your answers!
     
  2. volodya

    volodya wasm.ru

    Публикаций:
    0
    Регистрация:
    22 апр 2003
    Сообщения:
    1.169
    The answer is "unlikely".

    If need be u can always use the third party software holes. For example, I've heard a lot of rumors about aspi.sys driver. StarForce drivers. Firewall drivers. Dig them and then dig them again. May be you are lucky :)