Jump to content

Recommended Posts

Posted (edited)

Hey Guys,

 

As I found out today there is a huge gaping hole in Server 2008 R2,

 

MS have been informed about this hole on the 8th of this month- as yet they haven't released an update.

 

SO disable your RDP :)!

Edited by plexer
sensitive
Posted

Did your colleague discover + report this or has it been publicised on the net?

 

I ask because if it's not been publicised I'd probably not want to make as much info available as you have incase it provides enough info for someone to exploit it in the wild.

 

If it's been publicised already then fair enough.

Posted
lol I was only being sarcastic anyway about disabling RDp - just thought I'd let you all know about my findings, as for MS knowing all I know is it was submited to them on the 8th.
Posted
right, soooo. what?

 

Indeed. As it stands, what we get from this thread is that there is a threat to RDP on 2008 R2, but that we don't need to turn RDP off as you were joking.

 

So, on a scale of 1-10, with 10 being 'oh my god, our servers are going to go on a rampage eating children' and 1 being 'nothing to see here', we are at around 2...

Posted
Hi Guys, sorry for being vague been VERY Busy, I dont know much about the hole to be honest but it was a serious issue for me considering my Admin accounts got disabled, I can't go into to much detail but it was done from RDP, PM me if you want to know more.
Posted
Hi guys, a little more information which I found out today - the hole is in the Ease of Access feature at the logon screen, my colleague can manage to get the command prompt up from the ease of access, not usre how but he can and from there he can run mmc and then well all you need to do is add/remove snapins and viola!! your in!!!
  • Thanks 1
Posted

So if perchance someone had replaced the ease of access file within system32 with a fake one that just pops up and says "ease of access has been disabled by your administrator" this security hole isn't a problem? If that's the case i should be ok :)

 

EDIT: can i have a PM with the details to test?

Posted

The Ease of Access button can be made non-functional by using the following registry key...

 

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utilman.exe]
"Debugger"="%SystemRoot%\\System32\\Calc.exe"

 

Calc.exe will not run at the logon screen, so nothing happens when the button is clicked. :)

  • Thanks 1
Posted

 

My issue with that, Is it means the user needs to actually "change" the system. They're replacing the ease of access exe with a new exe. Which they shouldn't have access to do in the first place?

 

And even once they do that, they'd only have access to local files, aka roaming profiles etc wouldn't be accessible.

 

"imo" it's similar to saying install a keylogger and they can log in... Well yeah, but they shouldn't be able to? (Unless I missed something)

 

Steve

Posted
My issue with that, Is it means the user needs to actually "change" the system. They're replacing the ease of access exe with a new exe. Which they shouldn't have access to do in the first place?

^^ Exactly! I agree with the response Microsoft gave in that article. It's extremely easy to replace any file with a malicious one once you have physical access.

 

If this is the same "hole" which @cpjitservices is talking about, I would rate it 1 out of 10 on @localzuk's scale.

Posted
cpjitservices[/mention] is talking about' date=' I would rate it 1 out of 10 on [mention=1433']localzuk[/mention]'s scale.

 

There are some easy ways to access it, if you have access to it (but not sure about RDP) for example, using PE boot CD gives instant access to cmd. Run few "rename/copy" commands, and there you have access to any program through ease of access again. But again, need access to the machine at least :p

 

Steve

Posted
There are some easy ways to access it, if you have access to it (but not sure about RDP) for example, using PE boot CD gives instant access to cmd. Run few "rename/copy" commands, and there you have access to any program through ease of access again. But again, need access to the machine at least :p

 

Steve

 

Bitlocker helps out with this - not that every machine has a TPM chip in though......

Posted
So, on a scale of 1-10, with 10 being 'oh my god, our servers are going to go on a rampage eating children' and 1 being 'nothing to see here'

 

Hmmm - just noticed it's oddly quiet here, and my server has gone walkies.

 

Hang on, who could that be knocking on my door...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...