Re: Hacking Windows Security Principal

From: Chris Rolon (chris.rolon_at_removethis.neudesic.com)
Date: 01/31/05

  • Next message: Sathiyarajan Rajendran via DotNetMonster.com: "Re: Authorization Application Block/ COM object with CLSID exception"
    Date: Sun, 30 Jan 2005 21:09:03 -0800
    
    

    Even if your worst case scenario were to occur, as soon as your application
    tried to access a Windows resource it would fail. For one, the OS will know
    that the current user has not been authenticated and a challenge will
    result. If the user were authenticated and your next scenario were to occur,
    Windows would again catch it because the user does not belong to
    "FullControl".

    The WindowsPrincipal is an in memory representation of a user and the roles
    that the user is in. This does not mean that the OS will not verify against
    it's own information.

    -- 
    Chris Rolon
    "Rene" <nospam@nospam.com> wrote in message
    news:OvwpZg2AFHA.2676@TK2MSFTNGP12.phx.gbl...
    > According to my research, it looks like I can use the Windows Security
    > Principal to verify that a user is authenticated or to see if they belong
    to
    > a certain group etc.
    >
    > The thing that bothers me is that this object resides in the client
    computer
    > memory and everybody knows that this makes this object more vulnerable to
    > hacker attacks.
    >
    > My question is, how difficult would be for a hacker to go directly to
    memory
    > and flip the IsAuthenticated bit from 0 to 1? or go directly through
    memory
    > and change a group name from "ZeroControl" to "FullControl"? Once those
    > changes are made, the attacker would be able to easily bypass my roll base
    > security and I will be... Oh my, I don't even what to think about that.
    >
    > This is just a silly example but I hope it gets the point across, thank
    you
    > for any information.
    >
    >
    

  • Next message: Sathiyarajan Rajendran via DotNetMonster.com: "Re: Authorization Application Block/ COM object with CLSID exception"

    Relevant Pages

    • RE: Virtual memory
      ... You can configure virtual memory in windows xp and thereby improve the ... How to set performance options in Windows XP ... if you have background programs such as printing or disk ... It is also known as the paging file. ...
      (microsoft.public.windowsxp.perform_maintain)
    • [NT] NNTP Service in Windows Contains Memory Leak
      ... NNTP Service in Windows Contains Memory Leak ... An affected server could be restored to normal service by ...
      (Securiteam)
    • Re: Physical Memory
      ... These Windows services are started: ... Memory optimizers/defragers are nothing more than snake ... These optimizers work by making demands on the Windows Memory Manager ... The funny thing about all of this nonsense is that the snake oil memory ...
      (microsoft.public.windowsxp.general)
    • Re: Slow performance
      ... computer has two memory slots so to achieve 1 gb you need to install 2 x ... own set up consists of AVG 8 Anti-Virus, Spybot S& D, Windows Defender ... of programme is generally not recommended in these newsgroups. ... My disk drive is pretty full right now, mainly due to fact that I just ...
      (microsoft.public.windowsxp.perform_maintain)
    • Re: Physical Memory
      ... Thanks for your help, John. ... As for the services just use the Windows Services Management Console to ... Remote Access Connection Manager ... gig Pentium 4 processor and apparently a half gig of available memory, ...
      (microsoft.public.windowsxp.general)