I kinda didnt wanna spend more time on project asus my ass- except just removing it. it nagged me though- cuz the shit was def vulnerable....b Now i fire up a recording of my pc booted and see .... an easily exploitable move operation by asus crapware
-
-
What we wanna do is to redirect the files desination so in will get moved to a location we could not do our self. That location should then be trusted in a way that allows us to get the file executed under a higher privileged account.
Show this thread -
I still think my go to method for that works... when windows error reporting service runs as system it tries to load a not existing phoneinfo.dll from system 32. If not then every fucking gui process still desperately try to load the not existing edgegdi.dll .....
Show this thread -
The rename operation do not change the files destination though... How can we redirect the file move to another folder when we cannot transform the folder the existing file is in as it is not empty?
Show this thread -
Well... we dont have to! if we intially make the folder point to c:\temp\ the service will try to move c:\temp\file.exe to c:\recovery\file_s.exe
Show this thread -
if we then make an oplock on the file it open first- we can time it so that when we get the oplock callback, we know its now to change the junction folder so it now points to system32.
Show this thread -
We could also point the folder at "\RPC Control\" and in there make one symlink for source and one for destion. like this:pic.twitter.com/vqccARCQHA
Show this thread -
But this is all a crazy fantasy because in realitity it is impossible to create those symlinks or those oplocks- cuz they dont survive a reboot and we are not logged in yet.....
Show this thread -
This Tweet is unavailable.
-
We could also create the ntfs symbolic links on the recovery partition... Still needs admin though
Show this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.