Re: [Full-disclosure] Flaw in Microsoft Domain Account Caching Allows Local Workstation Admins to Temporarily Escalate Privileges and Login as Cached Domain Admin Accounts (2010-M$-002)



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Kurt Dillard said the following on 13/12/10 20:09:
So far I agree with Thor. Did I miss something? Has anyone demonstrated
using the locally cached credentials to access resources across the network?
So far I haven't seen anything new or interesting in this thread:

Since the procedure involves the disconnection from network, IMHO this "flaw"
only demonstrates that the physical access is equal to the root/Administrator
access.


Ciao,
luigi

- --
/
+--[Luigi Rosa]--
\

You talk like a Minbari, Commander.
Perhaps there was some small wisdom in letting your species survive.
--Neroon, "Legacies"
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAk0Gd6oACgkQ3kWu7Tfl6ZRGugCfcbXguUKxEoG7pNtr18gWp+gt
rtEAoJhq6+Xg89/dn5vbXL6yjlC/H+nG
=urN/
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: BIND9 SERVFAIL on some .gov addresses
    ... This implies a connectivity issue between your client and the nyc.gov nameservers, ... dig on our network would work. ... whether it's a nameserver asking for it or a client? ... Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/ ...
    (comp.protocols.dns.bind)
  • Re: [opensuse] Nokia Nseries and gnokii
    ... quality software, instead of what looks to be a second tier component ... update the software on a Nokia phone? ... they have to comply to national and network ... Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org ...
    (SuSE)
  • Re: Does there exist something like a networked filestorage
    ... You need GnuPG to verify this message ... > now like to fill them up with hard disks ... > them to a network but present them as one single filespace. ... device like Peter's ENBD, search freshmeat.net for "ENBD". ...
    (comp.os.linux.networking)
  • GnuPG vs Digital Certificates?
    ... I've noticed many applications can use GnuPG or digital ... certificates and I would like to standardize if possible on the solution ... Better Management for Network Security ...
    (Security-Basics)
  • Re: [opensuse] IPv6 firewall
    ... IPv6 has been in the works for many years (I first ... My mobile provider uses NAT 10.x.x.x addresses while the land network ... the US and Asian address requirements will increase usage ... Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org/ ...
    (SuSE)