Full Disclosure mailing list archives

RE: LSASS exploit win32 binary


From: bosborne () caltex com au
Date: Wed, 28 Apr 2004 13:36:06 +1000

for those who are testing... a "shutdown -a" will stop it shutting down
although a manual shutdown after that displays a "You do not have
permission to shut down this computer."

tested it on 3 xp boxes without appropriate patch, all crashed.



|---------+-------------------------------------->
|         |           "Chris Scott"              |
|         |           <cscott () fluidsmgmt com>    |
|         |           Sent by:                   |
|         |           full-disclosure-admin@lists|
|         |           .netsys.com                |
|         |                                      |
|         |                                      |
|         |           28/04/2004 01:00 PM        |
|         |                                      |
|---------+-------------------------------------->
  >--------------------------------------------------------------------------------------------------------------|
  |                                                                                                              |
  |        To:      <Q.Long () city ac uk>, <full-disclosure () lists netsys com>                                      |
  |        cc:                                                                                                   |
  |        Subject: RE: [Full-disclosure] LSASS exploit win32 binary                                             |
  >--------------------------------------------------------------------------------------------------------------|





Tested against Windows XP Pro without the appropriate patch, it crashes the
service and initiates a shutdown timer.

-----Original Message-----
From: full-disclosure-admin () lists netsys com
[mailto:full-disclosure-admin () lists netsys com] On Behalf Of
Q.Long () city ac uk
Sent: Tuesday, April 27, 2004 6:24 PM
Subject: [Full-disclosure] LSASS exploit win32 binary

hi kids.
here's the compiled version of LSASS exploit from k-otik ...
http://users.volja.net/exceed/RLsasrv.zip

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html





_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: