I have a bug where a user can create a file anywhere.
This file:
1.can have any name/ext
2.will be empty
3.must not exist. E.g you can't create c:\windows\win.ini
4. You can't edit it
I can DOS.Other ideas you would like to share?
/cc: @SandboxBear , @decoder_it , @tiraniddo
-
-
That is the only case where I can see an not content controllable file creation vulnerability being usefull. Remember, a file creation vuln is also a directory creation vuln. Just append ::$INDEX_ALLOCATION
-
I Just got an idea.... You can create an alternative data stream on the primary hard drive root C:\:stream:$data - then afterwards you can open the file with FILE_APPEND_DATA because of FILE_APPEND_DATA S-1-5-11 (NT AUTHORITY\Authenticated Users)
- Show replies
New conversation -
-
-
I like that. maybe I have a chance to chain somehow. Thanks for sharing. I was not aware of redirection files. Thx.
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.