The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Windows, IIS at risk from 'token kidnapping'
Time: 00:18 EST/05:18 GMT | News Source: ZDNet Australia | Posted By: Kenneth van Surksum

Hosting providers and IT professionals have been warned of a threat posed to Microsoft IIS Web servers through exploitation of vulnerabilities in Microsoft operating systems.

The vulnerability, known as "token kidnapping", is a technique for the elevation of privileges on Windows operating systems. The proof-of-concept for the technique was developed by Cesar Cerrudo, chief executive of security company Argeniss. It exploits weaknesses that affect Windows Server 2003 and 2008, as well as Windows XP and Vista.

The technique works by elevating privileges through exploiting accounts on IIS servers that have rights to impersonate a client after authentication, Cerrudo told ZDNet.com.au sister site ZDNet.co.uk. Impersonation is the ability of a thread to execute using different security information than the process that owns the thread. The accounts can be exploited by "kidnapping" the token, an object that describes the security context of a process or thread.

Write Comment
Return to News

  Displaying 576 through 576 of 576
Prev | First
  The time now is 9:47:24 AM ET.
Any comment problems? E-mail us
#576 By 4240821 (82.115.4.230) at 7/30/2025 10:55:49 PM
https://justpaste.me/aYyE2
https://justpaste.me/dRPo1
https://justpaste.me/d6bO2
https://justpaste.me/fekx6
https://justpaste.me/f6uP1
https://justpaste.me/cUGo3
https://justpaste.me/fKlw1
https://justpaste.me/egrq1
https://justpaste.me/emwq5
https://justpaste.me/avAI1

Write Comment
Return to News
  Displaying 576 through 576 of 576
Prev | First
  The time now is 9:47:24 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *