[TOOL] XRunAs, Remote Command Execution

support_at_securiteam.com
Date: 04/28/03

  • Next message: support_at_securiteam.com: "[NT] JBoot Password Bypassing Vulnerability"
    To: list@securiteam.com
    Date: 28 Apr 2003 10:48:13 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    In the US?

    Contact Beyond Security at our new California office
    housewarming rates on automated network vulnerability
    scanning. We also welcome ISPs and other resellers!

    Please contact us at: 323-882-8286 or ussales@beyondsecurity.com
    - - - - - - - - -

      XRunAs, Remote Command Execution
    ------------------------------------------------------------------------

    DETAILS

     <http://lazysysadmin.com/> XRunAs is a tool that allows administrators to
    run commands on remote computers under the context of a specified user
    account without the use of the Schedule service. If XRunAs is used in
    conjunction with a domain account, commands that are run will be able to
    access network resources given that the domain account used to run the
    command has access to the network resource. All information that is
    transferred over the network while using XRunAs is encrypted using a
    standard encryption algorithm.

    ADDITIONAL INFORMATION

    The information has been provided by
    <mailto:lazysysadmin@tranquilsuds.com> LazySysadmin.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: support_at_securiteam.com: "[NT] JBoot Password Bypassing Vulnerability"

    Relevant Pages

    • XRunAs 1.1 - http://lazysysadmin.com/
      ... XRunAs is a tool that allows administrators to run commands on remote ... account, commands that are run will be able to access network resources ...
      (comp.os.ms-windows.nt.admin.security)
    • XRunAs 1.1 - http://lazysysadmin.com/
      ... XRunAs is a tool that allows administrators to run commands on remote ... account, commands that are run will be able to access network resources ...
      (microsoft.public.win2000.security)
    • Re: Bulk Insert
      ... Check the account and permissions for the SQL Server ... It needs to be a domain account with the ... network resources. ...
      (microsoft.public.sqlserver.security)
    • Re: Services fail to start
      ... it shouldn't but since you're changing to a domain account you must require network resources available to your service. ... Just remember mapped drives won't natively exist so always best to use UNC paths. ... Microsoft MVP [Windows] ...
      (microsoft.public.windows.server.general)