[NT] RunAs Sensitive Data Exposure

From: support@securiteam.com
Date: 11/18/01


From: support@securiteam.com
To: list@securiteam.com
Subject: [NT] RunAs Sensitive Data Exposure
Message-Id: <20011118173755.30C6D138BF@mail.der-keiler.de>
Date: Sun, 18 Nov 2001 18:37:55 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  RunAs Sensitive Data Exposure
------------------------------------------------------------------------

SUMMARY

The command line utility "RunAs" leverages the RunAs service in an effort
of launching an application in a distinct security context. However, the
utility does not properly erase the user credentials on exit, which makes
it possible for an attacker to read another user's credentials.

DETAILS

Applications that deal with highly sensitive data, such as user
credentials, must ensure that those credentials are sufficiently destroyed
after their use.

The RunAs utility performs no such destruction with credentials supplied
by the user. They are left, in plaintext, on the application's stack when
the application has terminated. Those credentials will be present when an
arbitrary application or driver has reallocated that particular allocation
page.

A malicious application could wait for a RunAs session to terminate then
subsequently search for that user's credentials. In order to execute this
vulnerability, the malicious user must have interactive access to the
Windows 2000 machine. Because of this, Windows 2000 Terminal services
would be most applicable for an attack.

Vendor information:
Microsoft has decided to include the fix within service pack 3 (SP3).

According to the Microsoft, "In February 2002, we will release Windows
2000 Service Pack 3 (SP3)".
 
<http://www.microsoft.com/presspass/features/2001/oct01/10-03securityqa.asp> http://www.microsoft.com/presspass/features/2001/oct01/10-03securityqa.asp

ADDITIONAL INFORMATION

The information has been provided by <mailto:research@camisade.com> Team
RADIX -- Camisade LLC.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NT] Citrix MetaFrame Password Manager Credentials Not Encrypted Under Certain Configurations
    ... Get your security news from a reliable source. ... encrypted database and automatically providing credentials to applications ... administrator inadvertently fails to configure the Citrix MetaFrame ... The local credential store is protected by Windows File Access Control ...
    (Securiteam)
  • RE: Hacker Stories, Certs, vs Projects - Was Re: Technitium MAC Address Changer v3.1 (FREEWARE)
    ... requirement of 6 years of security work prior to being eligible for the ... Most of which are new requirements instituted a few years ago when a very young Indian gentleman passed the CISSP exam earning the right and fame to claim as the o7ungest certified CISSP in existance. ... And I do know certified fewls that have not a single skill in security bascis nor a clue as to any concepts of networking. ... I'm sorry you fgeel so threatened cause your cert has such little real merit except to a HR rep or a clueless manager on the prowl for a cheap hire and a cya glance over of the credentials offered by a potential candidate for a position, ...
    (Pen-Test)
  • RE: Hacker Stories, Certs, vs Projects - Was Re: Technitium MAC Address Changer v3.1 (FREEWARE)
    ... general security credential. ... I understand that a CISSP can tell me that ... Credentials can only be looked at to strengthen the credibility of a ... Download FREE whitepaper on how a managed service ...
    (Pen-Test)
  • Re: Windows Authentication "ausloggen"
    ... dem Webserver die Integrated Security aktiviert ist. ... Damit werden bei einem Zugriff auf die Site die Credentials abgefragt. ... Die Inhalte der in dieser Newsgroup eingestellten Inhalte stammen von ... > Dazu soll sich der eigentliche PC Besitzer ausloggen und der Mitarbeiter, ...
    (microsoft.public.de.german.entwickler.dotnet.asp)
  • Re: Unable to access domain resources after smart card logon
    ... You probably should check in the IE security options to see ... for your intranet zone. ... In IE's Tools dropbox, Internet Options, Security tab, select ... >> credentials or if using XP Pro check to see if it has stored ...
    (microsoft.public.security)