Jump to content

sircrumpet

Active Members
  • Posts

    11
  • Joined

  • Last visited

Posts posted by sircrumpet

  1. hmmm, wonder if anyone here has heard more about this...

    On Dec. 15, a Russian programmer posted a description of a flaw that makes it possible to increase a user’s privileges on all of the company’s recent operating systems, including Vista. And over the weekend a Silicon Valley computer security firm said it had notified Microsoft that it had also found that flaw, as well as five other vulnerabilities, including one serious error in the software code underlying the company’s new Internet Explorer 7 browser.
    http://www.nytimes.com/2006/12/25/technolo...artner=homepage
  2. ok - my one concern here (and i havent tried it yet), but what would happen if someone came along with either an ipod or a portable HDD or something with say, 60Gb of data. I'm assuming it would read it in the same way it reads a flash drive and attempt to copy and email it off, but it would take more than a few seconds to copy over 60+ GB of data, even longer to email it off, and then theres the problem of the 2ish GB limit on Gmail.

  3. so i just switched over to DLSS's payload and plugged my usb into my computer at school (yes i do keep school work on it too) and i got a pop up message saying that windows could not find some .dll file (i should have written it down) and decided to restart in 60 seconds. I found this odd so let it restart and than plugged it in again. Same thing, i switched over to another comp and it happened again, I tried two more comps and this did not happen. The payload ran just fine and normal. Anyone have this same problem, or know whats going on? Thanks.

    Put simply, windows is complaining about the fact that one of the files on your switchblade (pwdump.exe) is attempting to steal the SAM file - Windows reads it as an error, and shuts down your computer to "protect your system"...

  4. It's not good practice to leave the Administrator account without a password. I'd urge you strongly to apply one. however straightforward it might be. It wouldn't stop a determined attacker, but what would? At least you'd put off those who might rely upon the simple trick given above.

    Agreed, its such a simple risk, but its one that is all too often ignored. It takes just a second to apply a password, and is well worth doing.

  5. I didn't think You can control the "Administrator" On Windows XP Home it is only there in Safe Mode.

    Press Ctrl+Alt+Del Twice on the login screen (or change the settings in Control Panel) to bring up the "traditional" login (which requires you to type user name/password), enter "Administrator" and leave the password blank.

  6. I'm new here, and not sure whats been covered or not, But I'd like to say the stuff the hak.5 crew does pushes me more to being a network administrator and learn everything there is to know about pc's, So Here's my way of forcing myself into Windows XP

    Some systems are different and if you push F12 and the Boot from CD: screen you can boot in safe mode and go into Administrator and add an Administrator account outside safe mode, Or F8 - F12 not sure which one at this White type Windows XP loading screen brings up the safe mode menu allowing you to do the same thing.

    that works, however it requires that no administrator password be set, and almost any computer running XP Professional or that is in a network (or has a reasonably smart admin) will almost certainly have a password set to the root admin account.

  7. hmmm... what moonlit has done is great, but I still feel that encrypting the exes would be an easier way to go about things...

    Pseudobreed's version seems to work well (although NOD32 absolutely HATES mailpv.exe), though it does a bit too much for what i want, and as such i've been playing around and editing it a bit...

    I'm also extremely curious as to whether anyone has found a program similar to the "IE PassView" that is included with many of these switchblades, but that will get the passwords out of Firefox as well...

  8. ahhhh stupid me :roll:

    It all makes sense now - I must of just discarded the whole "social engineering" comment describing the download :wink:

    Am playing with merging the two now...

    btw. you seem to be getting a fair bit of attention in the blogoshpere with this stuff ;)

  9. :( Unfortunately Amish's still seems to bug me with the "What do you want windows to do" message, and it doesn't copy the LM hashes either.

    If anyone works out fixes for these for those of us without a spare U3 drive it would be great :)

×
×
  • Create New...