Completely.
But @msftsecurity focus on others subject and doesn't make statements about [MS-EFSR]
-
-
Yes, and a good catch too in their documentation. It will be hard to justify NOFIX in face of this.
1 reply 0 retweets 3 likes -
Replying to @mkolsek @gentilkiwi and
I'm trying to understand the use case for the EfsRpcOpenFileRaw call. Who is supposed to make this call and on what kind of UNC path?
1 reply 0 retweets 1 like -
Backups :)
1 reply 0 retweets 2 likes -
yep it's a backup feature ignores file locks, too
1 reply 1 retweet 2 likes -
Thanks! So if we break this in any way, we break backup? Is this then completely broken by design then and literally couldn't be patched by MS?
2 replies 0 retweets 1 like -
You can retrieve files via that RPC call, unauthenticated. There's also a function to encrypt files... and remove decryption metadata.
2 replies 1 retweet 4 likes -
So which user account is making this call in a legitimate scenario? Backup operator?
1 reply 0 retweets 0 likes -
Replying to @mkolsek @GossiTheDog and
Normal flow is that first NTFS connects to lsass through an ALPC port. LSASS Then impersonates the caller and open the file to operate on. It opens with only FILE_READ_ATTRIBUTTE though it will then do IOCTLS that read and write anyway. ifsutilx.dll will handle the requests and
2 replies 0 retweets 3 likes -
i also stubled upon this... Ive alvays knew it was a lie https://support.microsoft.com/en-us/windows/how-reserved-storage-works-in-windows-10-5bc98443-0711-8038-4621-6a18ddc904f2 …
1 reply 0 retweets 1 like
to me it looks more like a place to stash the telemetric data- you cant submit data when bsod.....pic.twitter.com/PcHbK8LxgN
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.