Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Get admin rights using Doro (pdf creator)
From: Ramon Kukla <ml () portsonline net>
Date: Sun, 14 Dec 2003 22:06:41 +0100

Hi,

a few days ago i discovered a bug in Doro[1]. Doro is a free tool to
create pdf files from any windows program. After installing Doro you
have a new printer called 'Doro PDF Writer'.
If you select 'Print' the spooler calls the printer filter 'doro.dll'.
The 'doro.dll' then starts 'doro.exe' and a file requester appears.

I guess that most of you see the problem. The spooler is controlled by
the account 'system'. Therefore the file requester has the same rights.

It's easy now to create a new user and move them into the group
'admins'.

I informed the coder of the software and he approved the problem.


regards
Ramon

[1] http://www.geocities.com/the_real_sz/misc/doro.htm


  By Date           By Thread  

Current thread:
  • Get admin rights using Doro (pdf creator) Ramon Kukla (Dec 15)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]