Every process has access to free, silent elevation! Proof of concept video

    Every process has access to free, silent elevation! Proof of concept video


    Posted: 19 Feb 2009
    Oh boy. This guy shows that becuase of the way the new UAC whitelist works, it is possible to run any command with elevation and not raise a single UAC prompt!

    This first video gives some info about how the UAC whitelist works:

    Win7Elevate v2 proof-of-concept: Video demonstration of Win 7 Beta UAC flaws and design

    And this second video shows his injector program silently wiping the contents of system32 and utterly destroying the (virtual) OS:

    Win7Elevate v2 proof-of-concept: A more dramatic video

    The conclusion? UAC prompts only provide the illusion of security.

    I sure hope this gets fixed before the offical release
    Posted By: garbanzo
    19 Feb 2009



  1. Posts : 995
    XP/win7 x86 build 7127
       #1

    nice read garbanzo. Since i am admin, i run high all the time. Nevertheless, if this isnt fixed, alot of users will install this, and run their own accounts as admin and wont think to either change account type or raise UAC elevation....... scary as hell
      My Computer


  2. Posts : 5,840
    Vista Ult64, Win7600
       #2

    Hi,thanks for the read ,I sure hope they fix it fast ,at this stage I don't know if I should be just scared of UAC, or terrified of it.
      My Computer


  3. Posts : 575
    7600 x86
    Thread Starter
       #3

    the scary part about this is not that stupid users can misuse it, it's that it can be used maliciously! even with UAC on, malicious code can use the methods this guy is using to basically take control of a user's system without them knowing about it.

    at first the UAC whitelist just pissed me off because it is anti-competitive, since only windows processes can be whitelisted. now, it's clear that it represents a very serious security threat. these videos have been online for about 3 weeks now, i'm surprised i've not heard about this.

    am i overreacting? is this not as bad as it seems?
      My Computer


  4. Posts : 995
    XP/win7 x86 build 7127
       #4

    garbanzo said:

    am i overreacting? is this not as bad as it seems?
    We are on the same boat here. This is quite unbelievably unbelievable. How about a blacklist type option.... i mean calc and notepad? seriously!
      My Computer


  5. Posts : 336
    windows 7 X64
       #5

    sense viruses have to make it on the computer in the first place to do damage wouldnt a program like that have to make it on the computer to deal the deathblow..?

    seems like its nothing a good virus scan and smart computing cant take care of
      My Computer


  6. Posts : 18,404
    Windows 7 Ultimate x64 SP1
       #6

    You're forgetting about drive-by downloads and the like.

    In April 2007 researchers at Google discovered hundreds of thousands of web pages performing drive-by downloads.
    Drive-by download - Wikipedia, the free encyclopedia
      My Computer


  7. Posts : 336
    windows 7 X64
       #7

    Airbot said:
    You're forgetting about drive-by downloads and the like.

    Drive-by download - Wikipedia, the free encyclopedia
    doesnt most good virus scans prevent those as well... kaspersky or whatever seems to block alot of adds and webpages that come up as shady..
      My Computer


  8. Posts : 18,404
    Windows 7 Ultimate x64 SP1
       #8

    True, but a lot of people don't run AV's and the UAC will provide some protection against DBD's. And having both is better than just one, AV's can miss things, especially when new kinds/types of malware are made and spread about all over the place everyday. Zero Day threats that most AV's haven't had the chance to catch up with their malware definations fast enough.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 14:06.
Find Us