[a / b / c / d / e / f / g / gif / h / hr / k / m / o / p / s / t / u / v / vg / vm / vmg / vr / vrpg / vst / w / wg] [i / ic] [r9k / s4s / vip] [cm / hm / lgbt / y] [3 / aco / adv / an / bant / biz / cgl / ck / co / diy / fa / fit / gd / hc / his / int / jp / lit / mlp / mu / n / news / out / po / pol / pw / qst / sci / soc / sp / tg / toy / trv / tv / vp / vt / wsg / wsr / x / xs] [Settings] [Search] [Mobile] [Home]
Board
Settings Mobile Home
/g/ - Technology


Thread archived.
You cannot reply anymore.


[Advertise on 4chan]


File: 1784234960590564.jpg (113 KB, 1001x1024)
113 KB JPG
Based NightmareEclipse btfoing microslop with endless zero days.
He could have sold these all for tens of millions of dollars, instead, he chooses to BTFO Microsoft.

>The new bug, dubbed ShieldBreak, is the latest disclosure by security researcher Nightmare Eclipse, who in recent months has published details of several bugs affecting Microsoft’s products, including Windows.

>According to Nightmare Eclipse’s post, ShieldBreak takes advantage of a flaw in Windows Defender, the anti-malware and security engine built into Windows. A successful attack allows the hacker to escalate their permissions from a low-level user to full access to the device and its data.
>>
>While it claims to be a RoguePlanet bypass, I'll admit that my naive eyeballs fail to see the similarity.

>I've skipped a few minor points, but the general gist is:
>1) Set up a temp directory that's registered as a Cloud Sync provider.

> Plant an EICAR file
> Use Object Manager symlinks to control Defender's scan path to system32.
> During the scan, leverage CLFS to swap the identity file and hydration data to C:\Windows\system32\phoneinfo.dll (which doesn't exist by default in Windows)
> Run the QueueReporting scheduled task, which runs wermgr.exe -upload as Run with highest privileges

>In the wer.dll code, there is explicit code to load phoneinfo.dll. Because at this point, phoneinfo.dll exists and is our own code, this runs, spawning conhost.exe with SYSTEM privileges.
>>
>>109537125
m$ftbtfo + reeling
what about lawsuits?
can they even do anything?
>>
>>109537125
it is always the funniest when antivirus itself leads to system pwnage.



[Advertise on 4chan]

Delete Post: [File Only] Style:
[Disable Mobile View / Use Desktop Site]

[Enable Mobile View / Use Mobile Site]

All trademarks and copyrights on this page are owned by their respective parties. Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.