[TOOL] RegistryBrowser Allows Remote Registry Access to HKEY_CURRENT_USER

From: support@securiteam.com
Date: 11/27/01


From: support@securiteam.com
To: list@securiteam.com
Subject: [TOOL] RegistryBrowser Allows Remote Registry Access to HKEY_CURRENT_USER
Message-Id: <20011127215141.C6752138BF@mail.der-keiler.de>
Date: Tue, 27 Nov 2001 22:51:41 +0100 (CET)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  RegistryBrowser Allows Remote Registry Access to HKEY_CURRENT_USER
------------------------------------------------------------------------

DETAILS

The Microsoft Windows Registry Editor can view five predefined and
reserved keys in the registry. They are HKEY_LOCAL_MACHINE, HKEY_USERS,
HKEY_CURRENT_CONFIG, HKEY_CLASSES_ROOT, and HKEY_CURRENT_USER. The
HKEY_CURRENT_USER is a subkey of HKEY_USERS. It is the registry key used
by a user, who is currently logging on to the system.

When you log on Windows NT/2000 locally, you can edit your personal
registries in HKEY_USERS or HKEY_CURRENT_USER using the Registry Editor.
At the same time, HKEY_CURRENT_USER can be accessed and modified remotely.
 In other words, you can edit your personal registries (HKEY_CURRENT_USER)
using your account and password from a remote computer, given that you are
also logging on the target computer locally.

If your account and password are stolen, it becomes a very serious
security problem since someone who knows your account and password can
edit your personal registry settings.

RegistryBrowser is a utility that demonstrates this security issue. It
can browse remote system registry using a specified user account. Please
try to access HKEY_CURRENT_USER remotely when you either log on or log off
locally.

ADDITIONAL INFORMATION

The tool can be downloaded from:
 <http://www.securityfriday.com/Topics/win_reg.html>
http://www.securityfriday.com/Topics/win_reg.html

The information has been provided by <mailto:urity@securityfriday.com>
Urity.

========================================

This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: Registry access question
    ... or ownership of registry entries though Dolphin either (as you might want to ... I will take another look, but at first glance, but the remote part of it is scary. ... When it turns to remote administration, I get nervous, both from the standpoint of security and reliability. ... But to invoke a structured programming analogy, what is the real danger? ...
    (comp.lang.smalltalk.dolphin)
  • Re: Set Registry Remotely as non-administrator
    ... EVER THINK THAT IS A GOOD IDEA TO DUMB DOWN SECURITY FOR SOMETHING LIKE ... BUT Registry ACL are MUCH more difficult to modify without ... Is there a way to allow this for non-administrator users? ... I'm using to try to read/write registry on the remote machine. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Unsafe Poker Rooms
    ... "Unsafe Poker Rooms" doesn't have quite as much ... in clear text in the registry on your PC, or indeed any PC you play from. ... the PC to get your account credentials and clean you out. ... you wonder what other security holes the sites in question have if this is ...
    (rec.gambling.poker)
  • Re: Get/set local security settings programmatically
    ... We are aware of the registry settings and the WMI ... there are no native Win32 APIs for these two local security settings. ... Account policies include password policies ...
    (microsoft.public.platformsdk.security)
  • RE: Extracting NT password hashes from registry export file
    ... Extracting NT password hashes from registry export file ... This list is provided by the SecurityFocus Security Intelligence Alert Service. ...
    (Pen-Test)