The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Windows, IIS at risk from 'token kidnapping'
Time: 00:18 EST/05:18 GMT | News Source: ZDNet Australia | Posted By: Kenneth van Surksum

Hosting providers and IT professionals have been warned of a threat posed to Microsoft IIS Web servers through exploitation of vulnerabilities in Microsoft operating systems.

The vulnerability, known as "token kidnapping", is a technique for the elevation of privileges on Windows operating systems. The proof-of-concept for the technique was developed by Cesar Cerrudo, chief executive of security company Argeniss. It exploits weaknesses that affect Windows Server 2003 and 2008, as well as Windows XP and Vista.

The technique works by elevating privileges through exploiting accounts on IIS servers that have rights to impersonate a client after authentication, Cerrudo told ZDNet.com.au sister site ZDNet.co.uk. Impersonation is the ability of a thread to execute using different security information than the process that owns the thread. The accounts can be exploited by "kidnapping" the token, an object that describes the security context of a process or thread.

Write Comment
Return to News

  Displaying 301 through 303 of 303
Prev | First
  The time now is 4:31:28 AM ET.
Any comment problems? E-mail us
#301 By 4240821 (212.193.138.162) at 11/25/2024 10:51:23 AM
https://www.google.af/amp/s/lustful.su/get/a182/a182pdncqhwcxvhokgh.php
https://www.google.am/amp/s/lustful.su/get/a139/a139mxiaikpfmatzdpu.php
https://www.google.ag/amp/s/lustful.su/get/a111/a111rtddbukpryrtxth.php
https://www.google.ag/amp/s/lustful.su/get/a13/a13hxztcdvxhaspqpu.php
https://www.google.af/amp/s/sexonly.su/get/a166/a166fqtggtmsldsgqiv.php
https://www.google.am/amp/s/sluts.su/get/a99/a99byubaconyiyupqm.php
https://www.google.ae/amp/s/nsfw.su/get/a247/a247pohttdivvufdqdf.php
https://www.google.ae/amp/s/nsfw.su/get/a190/a190dfwurmkvqrpdpkr.php
https://www.google.ae/amp/s/sexonly.su/get/a145/a145lrwriwizcpbsbcv.php
https://www.google.ag/amp/s/nsfw.su/get/a93/a93heczysslxkykavl.php

#302 By 4240821 (212.193.138.162) at 11/26/2024 1:28:33 AM
https://justpaste.me/Bs5M1
https://justpaste.me/CI4j
https://justpaste.me/CNrb3
https://justpaste.me/C4mH1
https://justpaste.me/CCFR3
https://justpaste.me/C2Zc1
https://justpaste.me/C9pH
https://justpaste.me/C3s0
https://justpaste.me/C2Pg
https://justpaste.me/CED11

#303 By 4240821 (82.117.86.164) at 11/26/2024 7:08:06 PM
https://justpaste.me/Brtw2
https://justpaste.me/C6OU1
https://justpaste.me/CJuK1
https://justpaste.me/CRPH2
https://justpaste.me/CSza1
https://justpaste.me/CJWD5
https://justpaste.me/CAVg3
https://justpaste.me/CQjD2
https://justpaste.me/CAVg3
https://justpaste.me/CKcs3

Write Comment
Return to News
  Displaying 301 through 303 of 303
Prev | First
  The time now is 4:31:28 AM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *