lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <4814099281.20031214220441@portsonline.net>
From: ml at portsonline.net (Ramon Kukla)
Subject: Get admin rights using Doro (pdf creator)

Hi,

a few days ago i discovered a bug in Doro. Doro is a free tool to
create pdf files from any windows program. After installing Doro you
have a new printer called 'Doro PDF Writer'.
If you select 'Print' the spooler calls the printer filter 'doro.dll'.
The 'doro.dll' then starts 'doro.exe' and a file requester appears.

I guess that most of you see the problem. The spooler is controlled by
the account 'system'. Therefore the file requester has the same rights.

It's easy now to create a new user and move them into the group
'admins'.

I informed the coder of the software and he approved the problem.


regards
Ramon


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ