PDA

View Full Version : New 2-Step Vista UAC Hack Revealed.


anandk
17-05-2007, 08:21 AM
"A Web application developer has uncovered a two-step process (PDF) for exploiting Windows Vista's User Account Control, essentially by having a Trojan piggyback on what could be a legitimate download...

...the vulnerability uses a two-part attack vector against a default Vista installation. The first step requires that malware called a proxy infection tool be downloaded and run without elevation. That software can behave as the victim expects it to while it sets up a second malicious payload in the background..."

source (http://www.eweek.com/article2/0,1759,2131595,00.asp?kc=EWRSS03119TX1K0000594)
whitepaper (http://www.robpaveza.net/VistaUACExploit/UACExploitWhitepaper.pdf)

techtronic
17-05-2007, 11:33 PM
Buddy, shouldn't this be in Tech News Section
Just now read it in Neowin.
Damn, these guys are pretty fast in breaking whatever Microsoft release as part of their OS :D

eddie
17-05-2007, 11:45 PM
As the OS starts settling down...chinks in Vista's armour start showing themselves. I don't know how this post belongs in Chit Chat section though...

praka123
18-05-2007, 12:44 AM
Now who wants to see VIsta's vulnerabilities?
....So this thread is here..not in tech news..gifted brains!!!
UAC..is it supposed to be a rip off UNIX?