Jun 13, 2009

Exploit code for Windows 7 injection vulnerability RELEASED!



12th June 2009: Binaries and Source Code Released

Sod it:
Since MS say this is such a non-issue and have ignored my offers to give them the full details for over four months they can't mind me posting the app, source code and full details in public.

As well as the C++ code, the source archive contains a text file describing both parts of the method I'm using in detail, including information about the CRYPTBASE.DLL thing which I've not published before (mainly because it isn't that interesting, TBH; it's just the final link in the chain).

Having released the binaries, MS can probably block them via Windows Defender or plug the CRYPTBASE.DLL hole, and that might cause people to say "they've fixed it, stop complaining," but unless they fix the underlying code-injection / COM elevation problem the file copy stuff will still work. Fixing only the CRYPTBASE.DLL part, or blocking the particular EXE or DLL, will just mean I or someone else has to find another slightly different way to take advantage of the file copy part which MS seem unwilling/unable to fix (or even admit is a problem at all). Finding the CRYPTBASE.DLL method took all of about 10 minutes so I'd be surprised if finding a replacement will be hard.

Source: Windows 7 UAC whitelist
Video: Video demonstration source

No comments:

Boorkmark & Share

Bookmark Options