Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

APG Classmaster Workstation Windows SMB share access vulnerability
From: Alex Garrett <alex () exploitthissite org>
Date: 21 Apr 2005 11:50:33 -0000



Greetings,

This vulnerability affects (I believe) all APG Classmaster Workstation
versions. It remains a problem as an attacker can access shares with full permissions over a LAN.

An attackers needs to issue a simple command in an MSDOS prompt (using the net windows application), mapping an account 
to a specified drive, as below:

net use [drive]: \\[server]\[user]$

A DIR command at this stage gives an access denied error. Knowing the name of the files area (which will be the same 
for each user) can lead to changing directory to that folder...

cd 'My files'

An attacker now has full permissions on a selected users 'my files' area.



Alex Garrett


  By Date           By Thread  

Current thread:
  • APG Classmaster Workstation Windows SMB share access vulnerability Alex Garrett (Apr 21)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]