RE: More on Shatter

From: Kris Kistler (krisk@kbeta.com)
Date: 08/26/02


From: "Kris Kistler" <krisk@kbeta.com>
To: <vuln-dev@securityfocus.com>
Date: Sun, 25 Aug 2002 20:26:29 -0500

While I haven't tested this particular piece of code remotely, it should be
noted that when access is provided via Terminal Services, Citrix MF, PcAny,
or with any countless number of other "remote access" type services, any
code run is running in the "local machine" context, which makes this and
many other "local" exploits actually quite dangerous.
K

> -----Original Message-----
> From: HalbaSus [mailto:halbasus@go.ro]

> 3. As long as someone needs phisical access for this it's not
> really such a
> serious problem.. usually when someone has phisical access to a
> computer he
> can do mostly whatever he/she wants. Without using exploits...
> 4. And probably the most important reason: Shatter is one of those mostly
> harmless yet very neet exploits that you can impress your friends
> with... or



Relevant Pages

  • Printing to shared local printer via Terminal Services
    ... servers running Windows 2000 Server, ... All computer work is done via terminal services. ... When connecting, she ... I have replaced the drivers on the local machine, ...
    (microsoft.public.windows.terminal_services)
  • SPs, sqlCommand and Terminal Services
    ... >statements executes the ... >this on a local machine, ... >run my application on a server using Terminal Services ...
    (microsoft.public.dotnet.framework.adonet)
  • Re: running an app locally
    ... "johnfli" wrote in message ... > Is there a way that if I have a user in Terminal Services, ... > a program open, when they save it, it will save on their local machine? ... you can map the remote drives on the TS so the file ...
    (microsoft.public.windows.terminal_services)
  • Invoking local Outlook object
    ... i have users working on my VB.net application over Terminal Services. ... running on there local machine and attach a copy of the report that they ... Now i want to invoke this same behavior from my ... the local outlook's New Mail window and an ASP.net application. ...
    (microsoft.public.dotnet.framework.aspnet)
  • Invoking Local Outlooks New Email Window
    ... i have users working on my VB.net application over Terminal Services. ... running on there local machine and attach a copy of the report that they ... Now i want to invoke this same behavior from my ... the local outlook's New Mail window and an ASP.net application. ...
    (microsoft.public.dotnet.framework.aspnet)