Bugtraq mailing list archives

Re: Process Killing - Playing with PostThreadMessage


From: "Maxime Ducharme" <maxime () pandore-design com>
Date: Fri, 3 Oct 2003 11:42:38 -0400


AFAIK, PostThreadMessage only works on local machine.

pskill will also ask for a password, Brett's code will bypass
security checks (tested on my win2k sp4 systems).

Correct me too if I'm wrong :-)

Ciao

---------------------------------------------------------------
  Maxime Ducharme
  Administrateur reseau, Programmeur
  Pandore-Design [http://www.pandore-design.com]


----- Original Message ----- 
From: "Thor Larholm" <thor () pivx com>
To: "Brett Moore" <brett.moore () security-assessment com>;
<bugtraq () securityfocus com>
Sent: Thursday, October 02, 2003 1:38 PM
Subject: Re: Process Killing - Playing with PostThreadMessage


Feel free to correct me if I am wrong, but isn't this also how the PSKill
application from SysInternals work?

http://www.sysinternals.com/ntw2k/freeware/pskill.shtml



Regards
Thor Larholm
PivX Solutions, LLC - Senior Security Researcher


----- Original Message ----- 
From: "Brett Moore" <brett.moore () security-assessment com>
To: <bugtraq () securityfocus com>
Sent: Wednesday, October 01, 2003 10:28 PM
Subject: Process Killing - Playing with PostThreadMessage



=========================================================================
= Process Killing - Playing with PostThreadMessage
=
= brett.moore () security-assessment com
= http://www.security-assessment.com
=
= Originally posted: October 02, 2003

=========================================================================
<snip http://msgs.securepoint.com/cgi-bin/get/bugtraq0310/23.html>




Current thread: