I still think my go to method for that works... when windows error reporting service runs as system it tries to load a not existing phoneinfo.dll from system 32. If not then every fucking gui process still desperately try to load the not existing edgegdi.dll .....
-
Show this thread
-
The rename operation do not change the files destination though... How can we redirect the file move to another folder when we cannot transform the folder the existing file is in as it is not empty?
1 reply 0 retweets 4 likesShow this thread -
Well... we dont have to! if we intially make the folder point to c:\temp\ the service will try to move c:\temp\file.exe to c:\recovery\file_s.exe
1 reply 0 retweets 4 likesShow this thread -
if we then make an oplock on the file it open first- we can time it so that when we get the oplock callback, we know its now to change the junction folder so it now points to system32.
1 reply 0 retweets 4 likesShow this thread -
We could also point the folder at "\RPC Control\" and in there make one symlink for source and one for destion. like this:pic.twitter.com/vqccARCQHA
1 reply 0 retweets 6 likesShow this thread -
But this is all a crazy fantasy because in realitity it is impossible to create those symlinks or those oplocks- cuz they dont survive a reboot and we are not logged in yet.....
1 reply 0 retweets 3 likesShow this thread -
This Tweet is unavailable.
-
or maybe use a driver bug for this... if you open a csc path using ipv6 localhost and add an unneeded backslash it will calculate the size of the buffer it redirect to wrong. So 1 byte pool memory will become part of the file name...
1 reply 0 retweets 4 likesShow this thread -
if we create junction folders with for each possible value the filename end up as we can do there is more or less 50/50 where the path will resolve to
1 reply 0 retweets 2 likesShow this thread -
or.. maybe I am stucked thinking in the old ways....lets turn this upside down. We could make the service move a file from to a location where another service will setacl on it that is more permissive.pic.twitter.com/IDulrmno96
1 reply 2 retweets 8 likesShow this thread
These files are hard links to the same file in system32- so if you setacl on the one in sxs it also applies to the one in system32
-
-
Replying to @jonasLyk1 reply 0 retweets 0 likes
-
Replying to @hackerfantastic
Hi! you can read it here: I kinda didnt wanna spend more time on project asus my ass- except… https://threadreaderapp.com/thread/1419770170998984705.html … Talk to you soon.
0 replies 0 retweets 2 likes
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.