[39915] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Local privilege escalation using runasp V3.5.1

daemon@ATHENA.MIT.EDU (securityfocus.5.stele@spamgourmet.)
Tue Jul 26 15:41:39 2005

Date: 26 Jul 2005 16:35:12 -0000
Message-ID: <20050726163512.30099.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: securityfocus.5.stele@spamgourmet.com
To: bugtraq@securityfocus.com

Hello,

this is not a RunAs Pro Bug.
-> Critical Files should be protected by Administrators, so that normal users are not able to rename them.
Just optimize your User-Permissions.

-> Just note:
Our next release will include a CRC32 Check of the file.

home help back first fref pref prev next nref lref last post