• [^] # privilege escalation inhérente à win

    Posté par . En réponse à la dépêche Linux et IBM reçoivent un satisfecit de Washington. Évalué à 2.

    tu es 1 intrus
    tu as réussi à accéder aux droits du service S via une faille dans ce service
    si un utilisateur U est connecté (ou se connecte ensuite)et a des fenetres ouvertes alors tu peux utiliser l'exploit évoqué plus haut pour accéder aux droits de U

    je cite http://informatics.ntu.edu.au/staff/kgilbert/security/shatter_attac(...)

    Any application on a given desktop can send a message to any window on the same desktop, regardless of whether or not that window is owned by the sending application, and regardless of whether the target application wants to receive those messages. There is no mechanism for authenticating the source of a message; a message sent from a malicious application is indistinguishable from a message sent by the Windows kernel.