| Thread Tools |
19th October 2018, 10:48 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| A simple Windows hack is unfixed a year later All a hacker could want A simple Windows security hack which was discovered a year ago is still unpatched. Discovered by Sebastián Castro, a security researcher for CSL, the technique targets one of the parameters of Windows user accounts known as the Relative Identifier (RID). It delivers the hacker admin rights and boot persistence on Windows PCs that's simple to execute and hard to stop. For some reason, though, the flaw has not been patched and it has not received either media coverage. Fortunately, the hackers have not spotted it either, and it has not been part of any malware campaigns. The RID is a code added at the end of account security identifiers (SIDs) that describes that user's permissions group. There are several RIDs available, but the most common ones are 501 for the standard guest account, and 500 for admin accounts. Castro, with help from CSL CEO Pedro García, discovered that by tinkering with registry keys that store information about each Windows account, he could modify the RID associated with a specific account and grant it a different RID, for another account group. A hacker cannot remotely infect a computer unless that computer has been left exposed on the Internet without a password. But it helps when a hacker has a foothold on a system. The hacker can give admin permissions to a compromised low-level account and gain a permanent backdoor with full SYSTEM access on a Windows PC. https://fudzilla.com/news/47415-a-si...d-a-year-later |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Windows 10 Buggy Updates? Our Patching Is Simple, Regular, Consistent Says Microsoft | Stefan Mileschin | WebNews | 0 | 7th August 2018 11:27 |
Cortana can be used to hack Windows 10 PCs | Stefan Mileschin | WebNews | 0 | 14th June 2018 12:44 |
House Democrats adopt encrypted messaging after last year's hack | Stefan Mileschin | WebNews | 0 | 21st July 2017 07:51 |
Russians exploit Windows hack | Stefan Mileschin | WebNews | 0 | 3rd November 2016 12:54 |
Congressional leaders were briefed on DNC hack last year | Stefan Mileschin | WebNews | 0 | 15th August 2016 16:05 |
Facebook likes 10 year old’s bug hack | Stefan Mileschin | WebNews | 0 | 6th May 2016 07:08 |
Keyless entry systems are still vulnerable to simple hack | Stefan Mileschin | WebNews | 0 | 27th March 2016 10:29 |
FBI warned of a Sony-style hack in a report last year | Stefan Mileschin | WebNews | 0 | 26th December 2014 13:28 |
Dangerous IE 8 exploit remains unfixed by Microsoft, instead users are urged to upgra | Stefan Mileschin | WebNews | 0 | 7th May 2013 09:13 |
Windows RT jailbreak automates a complex hack | Stefan Mileschin | WebNews | 0 | 14th January 2013 10:09 |
Thread Tools | |
| |