lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20040119144327.30509.qmail@www.securityfocus.com>
Date: 19 Jan 2004 14:43:27 -0000
From: <the_sz@....co.uk>
To: bugtraq@...urityfocus.com
Subject: Re: Get admin rights using Doro (pdf creator)


In-Reply-To: <7814219078.20031214220641@...tsonline.net>

I'm the author of Doro. Version 1.15 fixes this problem.

run.to/sz


>Received: (qmail 2135 invoked from network); 15 Dec 2003 20:22:15 -0000
>Received: from outgoing2.securityfocus.com (205.206.231.26)
>  by mail.securityfocus.com with SMTP; 15 Dec 2003 20:22:15 -0000
>Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20])
>	by outgoing2.securityfocus.com (Postfix) with QMQP
>	id 0FDF48FCEE; Mon, 15 Dec 2003 07:27:49 -0700 (MST)
>Mailing-List: contact bugtraq-help@...urityfocus.com; run by ezmlm
>Precedence: bulk
>List-Id: <bugtraq.list-id.securityfocus.com>
>List-Post: <mailto:bugtraq@...urityfocus.com>
>List-Help: <mailto:bugtraq-help@...urityfocus.com>
>List-Unsubscribe: <mailto:bugtraq-unsubscribe@...urityfocus.com>
>List-Subscribe: <mailto:bugtraq-subscribe@...urityfocus.com>
>Delivered-To: mailing list bugtraq@...urityfocus.com
>Delivered-To: moderator for bugtraq@...urityfocus.com
>Received: (qmail 13164 invoked from network); 14 Dec 2003 21:02:05 -0000
>Date: Sun, 14 Dec 2003 22:06:41 +0100
>From: Ramon Kukla <ml@...tsonline.net>
>X-Mailer: The Bat! (v2.01.3) Personal
>Reply-To: Ramon Kukla <ml@...tsonline.net>
>X-Priority: 3 (Normal)
>Message-ID: <7814219078.20031214220641@...tsonline.net>
>To: bugtraq@...urityfocus.com
>Subject: Get admin rights using Doro (pdf creator)
>MIME-Version: 1.0
>Content-Type: text/plain; charset=us-ascii
>Content-Transfer-Encoding: 7bit
>
>Hi,
>
>a few days ago i discovered a bug in Doro[1]. Doro is a free tool to
>create pdf files from any windows program. After installing Doro you
>have a new printer called 'Doro PDF Writer'.
>If you select 'Print' the spooler calls the printer filter 'doro.dll'.
>The 'doro.dll' then starts 'doro.exe' and a file requester appears.
>
>I guess that most of you see the problem. The spooler is controlled by
>the account 'system'. Therefore the file requester has the same rights.
>
>It's easy now to create a new user and move them into the group
>'admins'.
>
>I informed the coder of the software and he approved the problem.
>
>
>regards
>Ramon
>
>[1] http://www.geocities.com/the_real_sz/misc/doro.htm
>
>


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ