[CS-FSLUG] Windows token kidnapping returns to haunt Microsoft

Fred A. Miller fmiller at lightlink.com
Fri Jul 16 14:32:55 CDT 2010


Microsoft's problems with Token Kidnapping 
<http://www.argeniss.com/research/TokenKidnapping.pdf> [.pdf] on the 
Windows platform aren't going away anytime soon.

More than a year after Microsoft issue a patch 
<http://www.microsoft.com/technet/security/bulletin/MS09-012.mspx> to 
cover privilege escalation issues that could lead to complete system 
takeover, a security researcher plans to use the Black Hat conference 
spotlight to expose new design mistakes and security issues that can be 
exploited to elevate privileges on all Windows versions including the 
brand new Windows 2008 R2 and Windows 7.

http://www.zdnet.com/blog/security/windows-token-kidnapping-returns-to-haunt-microsoft/6849?tag=nl.e589 


-- 
"Those who hammer their guns into plows will plow for those who do not."
Thomas Jefferson

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://ofb.biz/pipermail/christiansource_ofb.biz/attachments/20100716/94e06358/attachment.htm>


More information about the Christiansource mailing list