yo- here we go \\.\global\globalroot\device\mup\;lanmanredirector\.\localhost\c$\\windows\:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data:$data nul..\ /..\..\write.exe
-
-
Replying to @jonasLyk @aaaddress1
yap- it workspic.twitter.com/wY1YXUKtuT
1 reply 0 retweets 2 likes -
Replying to @jonasLyk
local device prefix is amazingpic.twitter.com/xhnDoSccha
1 reply 1 retweet 2 likes -
Replying to @aaaddress1
also wmic process call create \\.\harddiskvolume3\windows\write.exe
2 replies 0 retweets 2 likes -
Replying to @jonasLyk
btw the following symlink from MSDN should be wrong, right? \\?\GLOBALROOT\Device\Mup\C$\bar\foo.txt ^^^^^^^^^^^^^ correct one should be: \\?\GLOBALROOT\Device\Mup\::1\C$\bar\foo.txtpic.twitter.com/VoVkkiKzSK
1 reply 0 retweets 0 likes -
-
Replying to @jonasLyk
is that okay no ip addr in UNC path? I try to call calc directly from \dev\mup by above pattern but not work
3 replies 0 retweets 0 likes -
Replying to @aaaddress1
lol wtf- start run: \\;webdavredirector\http://live.sysinternals.com \davwwwroot\rammap.exe run rammap at high integrity? what is this- worlds laziest uac bypass?
1 reply 0 retweets 2 likes -
Replying to @jonasLyk
ugh... that's because we access rammap file via Samba right? that's a sure thing to bypass uac if user allow the prompt :( and that provider webdavredirector is cool.
pic.twitter.com/mCC12poQSZ
2 replies 0 retweets 1 like -
Replying to @aaaddress1
and about it being samba? I dont think so- but its possible. Thing is- its not possible to setup wedav for anon access- but that thing do it fine....maybe samba- or a filter that remove translate: F header
1 reply 0 retweets 0 likes
do samba also answer like this:pic.twitter.com/oCUjIyfIC9
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.