Privilege escalation in Shell Create Object Task Server https://docs.google.com/document/d/e/2PACX-1vTP5OvJToWToMOKyeMyPcIPJhqbnESgWY6dYje9seJY96-ezCEJbXsMkfMWhoqPRaCNRs6BOO7urQyF/pub …
-
Show this thread
-
Replying to @jonasLyk @buherator
Nice to see that trick being used, the vuln I created it for turned out to still be far too much hassle to exploit even with the delay (https://bugs.chromium.org/p/project-zero/issues/detail?id=921 … I think).
1 reply 0 retweets 8 likes -
Replying to @tiraniddo @buherator
defender totally locks up by it also :) and when they get it patched I post article with me bypassing the patch for this vulnerability
1 reply 0 retweets 3 likes -
and that article maybe be relevant for the VHDMP..... it sure involves some of the same concepts and stuff :)
1 reply 0 retweets 1 like -
or maybe ill get around to article about oplocks++ first- I call it dreadlocks, with them you can "oplock" dir listings or create a file with the name of a file about to be created even if it is a unknown random filename :)
1 reply 0 retweets 1 like -
Replying to @jonasLyk @buherator
Well SetOpLock in my tools can already oplock on dir listings, just pass it a path to a dir. Though not see any ability to actually block the creation of files themselves till after they've given you the name :-)
1 reply 0 retweets 3 likes
They can trigger an oplock event- but the directory listing do not get paused until you allow it to continue
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.