The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Windows, IIS at risk from 'token kidnapping'
Time: 00:18 EST/05:18 GMT | News Source: ZDNet Australia | Posted By: Kenneth van Surksum

Hosting providers and IT professionals have been warned of a threat posed to Microsoft IIS Web servers through exploitation of vulnerabilities in Microsoft operating systems.

The vulnerability, known as "token kidnapping", is a technique for the elevation of privileges on Windows operating systems. The proof-of-concept for the technique was developed by Cesar Cerrudo, chief executive of security company Argeniss. It exploits weaknesses that affect Windows Server 2003 and 2008, as well as Windows XP and Vista.

The technique works by elevating privileges through exploiting accounts on IIS servers that have rights to impersonate a client after authentication, Cerrudo told ZDNet.com.au sister site ZDNet.co.uk. Impersonation is the ability of a thread to execute using different security information than the process that owns the thread. The accounts can be exploited by "kidnapping" the token, an object that describes the security context of a process or thread.

Write Comment
Return to News

  Displaying 201 through 205 of 205
Prev | First
  The time now is 7:40:43 AM ET.
Any comment problems? E-mail us
#201 By 4240821 (80.73.244.53) at 8/27/2024 11:44:21 AM
https://bio.site/namoragab240
https://bio.site/lakontoti489
https://bio.site/ovspopgerbles580
https://bio.site/chiodislectsunb963
https://bio.site/unpousine525
https://bio.site/venlachapheck663
https://bio.site/ricipitthi530
https://bio.site/starnarito588
https://bio.site/tisulphopor199
https://bio.site/procsepena722

#202 By 4240821 (212.193.138.162) at 8/27/2024 10:08:13 PM
https://bio.site/glynhochsrate907
https://bio.site/ogcusopor585
https://bio.site/tertoispirmai752
https://bio.site/randusttales431
https://bio.site/flypadnori546
https://bio.site/bioflethordi204
https://bio.site/namoragab240
https://bio.site/spirartale836
https://bio.site/imavarbreed120
https://bio.site/tisulphopor199

#203 By 4240821 (212.193.138.162) at 8/29/2024 11:02:16 PM
https://bio.site/tirostdwintest106
https://bio.site/rensducponal176
https://bio.site/glynhochsrate907
https://bio.site/pietagoldta489
https://bio.site/tertoumare382
https://bio.site/singtilanglust296
https://bio.site/petmanaje818
https://bio.site/ricipitthi530
https://bio.site/gravchimurge137
https://bio.site/trimunapor83

#204 By 4240821 (195.208.3.68) at 10/5/2024 9:24:28 AM
https://bio.site/srelizizet505
https://bio.site/stepelamri688
https://bio.site/ditasija693
https://bio.site/petiriri556
https://bio.site/gigerloni527
https://bio.site/ficlbiggcrouchwing51
https://bio.site/mierividsa555
https://bio.site/reibedgezi463
https://bio.site/plasseirase938
https://bio.site/declotplasle468

#205 By 4240821 (62.76.153.72) at 10/5/2024 7:20:19 PM
https://allmyfaves.com/achefsurppa154
https://allmyfaves.com/scufcotvoilen241
https://allmyfaves.com/cerleguce582
https://allmyfaves.com/outrettibal664
https://allmyfaves.com/vidacega940
https://allmyfaves.com/pillmamvianos159
https://allmyfaves.com/clubliferrbo901
https://allmyfaves.com/anhusonis352
https://allmyfaves.com/exerseder292
https://allmyfaves.com/exgacomdo362

Write Comment
Return to News
  Displaying 201 through 205 of 205
Prev | First
  The time now is 7:40:43 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *