I have a bug where a user can create a file anywhere.
This file:
1.can have any name/ext
2.will be empty
3.must not exist. E.g you can't create c:\windows\win.ini
4. You can't edit it
I can DOS.Other ideas you would like to share?
/cc: @SandboxBear , @decoder_it , @tiraniddo
Since the file is empty you now control 100% the content of a file that have a location that is likely to be unexspected. Create an symbolic link in NT Object Namespace with .exe targetting it to execute the file. That is a persistence technique thats easy to miss :)
-
-
Dir /R executed in C:\ will not even show the file
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.