tu es 1 intrus
tu as réussi à accéder aux droits du service S via une faille dans ce service
si un utilisateur U est connecté (ou se connecte ensuite)et a des fenetres ouvertes alors tu peux utiliser l'exploit évoqué plus haut pour accéder aux droits de U
Any application on a given desktop can send a message to any window on the same desktop, regardless of whether or not that window is owned by the sending application, and regardless of whether the target application wants to receive those messages. There is no mechanism for authenticating the source of a message; a message sent from a malicious application is indistinguishable from a message sent by the Windows kernel.
[^] # privilege escalation inhérente à win
Posté par free2.org . En réponse à la dépêche Linux et IBM reçoivent un satisfecit de Washington. Évalué à 2.
tu as réussi à accéder aux droits du service S via une faille dans ce service
si un utilisateur U est connecté (ou se connecte ensuite)et a des fenetres ouvertes alors tu peux utiliser l'exploit évoqué plus haut pour accéder aux droits de U
je cite http://informatics.ntu.edu.au/staff/kgilbert/security/shatter_attac(...)
Any application on a given desktop can send a message to any window on the same desktop, regardless of whether or not that window is owned by the sending application, and regardless of whether the target application wants to receive those messages. There is no mechanism for authenticating the source of a message; a message sent from a malicious application is indistinguishable from a message sent by the Windows kernel.