eWeek Security Watch
Advertisement
Advertisement
April 24, 2008 1:31 PM

Blue Hat: Token Kidnapping, Browser Security on Front Burner



Blue Hat: Token Kidnapping, Browser Security on Front Burner Software engineers at Microsoft will get a front-row seat to hear about an unpatched Windows security hole that was once pooh-poohed as a "design issue" that shouldn't be seen as a security vulnerability.

At the Spring edition of Redmond's Blue Hat hacker conference, the software giant has invited Argeniss researcher Cesar Cerrudo to present his discovery of a new technique for elevating privileges on Windows, mostly from services.

The technique exploits design weaknesses in Microsoft Windows XP, Windows Server 2003, Windows Vista, and even Windows Server 2008.

Cerrudo, a well-respected hacker who is known for discovering major bugs in Oracle, IBM and Microsoft products, presented the Token Kidnapping (.pdf) talk at the Hack in the Box conference in Dubai earlier this month.

[ SEE: Microsoft (Belatedly) Admits to Windows Server 2008 Token Kidnapping ]

Immediately after that presentation, Microsoft released a pre-patch advisory with the following warning:

Specially crafted code running in the context of the NetworkService or LocalService accounts may gain access to resources in processes that are also running as NetworkService or LocalService. Some of these processes may have the ability to elevate their privileges to LocalSystem, allowing any NetworkService or LocalService processes to elevate their privileges to LocalSystem as well.

At Blue Hat, Cerrudo will explain the intricacies of the attack and will provide zero-day code for elevating privileges in SQL Server 2005 and Internet Information Sevices 6 and 7, according to the Blue Hat session description posted online.

The security models of Web browsers, anti-virus software and browser plug-ins will also get top billing at Blue Hat. Also on the schedule is an update on Billy Rios and Nitesh Dhanjani's talk on the underground identity theft economy.

Create, Communicate, Collaborate with IT Professionals at Ziff Davis Enterprise IT Link

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/13406

Comments (1)

oregonnerd :

...Interesting. Same access process.
--G

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise