<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Root777 &#187; Do no Evil!</title>
	<atom:link href="http://www.root777.com/category/do-no-evil/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.root777.com</link>
	<description>Computer Security &#38; Technology</description>
	<lastBuildDate>Tue, 27 Jul 2010 02:25:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<image>
  <link>http://www.root777.com</link>
  <url>http://www.root777.com/favicon.ico</url>
  <title>Root777</title>
</image>
		<item>
		<title>Why is Windows so expensive?</title>
		<link>http://www.root777.com/do-no-evil/why-is-windows-so-expensive/</link>
		<comments>http://www.root777.com/do-no-evil/why-is-windows-so-expensive/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 01:15:30 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Do no Evil!]]></category>
		<category><![CDATA[Bing]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[googlebombing]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[search]]></category>

		<guid isPermaLink="false">http://www.root777.com/?p=120</guid>
		<description><![CDATA[If you type in the query of Why is Windows so expensive? or Why is Microsoft Windows so expensive? on Microsoft&#8217;s search engine bing.com returns the top result as &#8220;Why are Macs so expensive&#8221;. This is rather disappointing where bing seemed ready to give Google a challenge in the search engine space. Following are the [...]]]></description>
			<content:encoded><![CDATA[<p></p><p>If you type in the query of <strong><a title="Why is Windows so expensive" href="http://www.bing.com/search?q=Why+is+Windows+so+expensive%3F&amp;go=&amp;form=QBRE" target="_blank">Why is Windows so expensive?</a> </strong>or <strong>Why is Microsoft Windows so expensive?</strong> on Microsoft&#8217;s search engine <a title="Microsoft Bing" href="http://www.bing.com" target="_blank">bing.com</a> returns the top result as &#8220;Why are Macs so expensive&#8221;. This is rather disappointing where bing seemed ready to give Google a challenge in the search engine space.</p>
<div id="attachment_121" class="wp-caption aligncenter" style="width: 507px">
	<img class="size-full wp-image-121" title="Why is Windows so expensive." src="http://www.root777.com/wp-content/uploads/2009/08/Why-is-Windows-so-expensive..JPG" alt="Why is Windows so expensive." width="507" height="236" />
	<p class="wp-caption-text">Why is Windows so expensive.</p>
</div>
<p><span id="more-120"></span></p>
<p><strong>Following are the top results from Bing:</strong></p>
<p>News about Why is Windows so expensive<br />
Why are Mac&#8217;s So Expensive? &#8211; Yahoo! Answers<br />
why so expensive?. &#8211; Games for Windows Live<br />
Why are vinyl windows so expensive? who provides them cheapest &#8230;<br />
Why are vinyl windows so expensive? who provides them cheapest? Find answers to this and many other questions on Trulia Voices, a community for you to find and share local &#8230;<br />
Why are windows hosting providers so expensive? &#8211; Community Server<br />
Community Server is the platform that powers rich blogging, discussions, and sharing web communities.<br />
Why are Macbooks so expensive? &#8211; Yahoo! Answers<br />
WikiAnswers &#8211; Why are Apple Macs so expensive<br />
Apple and Mac question: Why are Apple Macs so expensive? Macs are no more expensive &#8230; can save money by buying more advanced parts for a windows computer. Also, they are expensive &#8230;<br />
Windows Embedded Blog : Why is OSS Commercial Software So Expensive?<br />
Why are Macs so expensive? &#8211; TechSpot Troubleshooting<br />
Why are Macs so expensive?<br />
Why are Macs so expensive? techradar.com â&#8221; There are some good reasons not to choose a Mac when you &#8230; If I feel like Sony are charging too much for a Laptop with Windows I can get a &#8230;<br />
Why fish is so expensive! &#8211; Windows Live</p>
<p>This is the result from Google:</p>
<p>Why Windows Vista and Office 2007 are so Expensive Â The Firefox &#8230;<br />
Is Windows getting more expensive? &#8211; CNET News<br />
Windows 7 to be âoemore expensiveâ than Vista, XP<br />
Writing on the Wall: Why Windows is so expensive<br />
Why are vinyl windows so expensive? who provides them cheapest &#8230;<br />
Omfg Vista Is so Expensive &#8211; Windows Vista and Windows 7<br />
Why are HDTV wall mounts so expensive?<br />
Why is the IBM thinkpad x301 laptop so expensive with mediocre &#8230;<br />
Why are Macs so expensive? | News | TechRadar UK<br />
Gizmodo &#8211; The World&#8217;s Most Expensive Copy of Windows XP &#8211; XP</p>
<p><strong>Update: </strong>Microsoft seems to have fixed this.</p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=120&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/do-no-evil/why-is-windows-so-expensive/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Dan Kaminsky gets hacked</title>
		<link>http://www.root777.com/do-no-evil/dan-kaminsky-gets-hacked/</link>
		<comments>http://www.root777.com/do-no-evil/dan-kaminsky-gets-hacked/#comments</comments>
		<pubDate>Fri, 31 Jul 2009 02:01:16 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Do no Evil!]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[Dan Kaminsky]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[WordPress]]></category>
		<category><![CDATA[wordpress security]]></category>

		<guid isPermaLink="false">http://www.root777.com/?p=118</guid>
		<description><![CDATA[Noted security professional Dan Kaminsky&#8217;s personal website was hacked into and personal information was stolen from his webserver and posted online on the eve of the Black Hat security conference. The stolen files included private emails between Dan and other security researchers. Following is the cached result of Dan Kaminsky&#8217;s website which is currently offline. [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><img class="alignleft" title="Dan Kaminsky picture" src="http://farm4.static.flickr.com/3477/3773193663_9951b765dc_o.jpg" alt="" width="240" height="160" />Noted security professional <a title="Dan Kaminsky" href="http://www.doxpara.com/" target="_blank">Dan Kaminsky&#8217;s personal website</a> was hacked into and personal information was stolen from his webserver and posted online on the eve of the <a title="Black Hat" href="http://www.blackhat.com/" target="_blank">Black Hat</a> security conference. The stolen files included private emails between Dan and other security researchers.</p>
<p>Following is the cached result of Dan Kaminsky&#8217;s website which is currently offline.</p>
<div class="wp-caption alignnone" style="width: 496px">
	<img title="Dan Kaminsky Hacked" src="http://farm4.static.flickr.com/3523/3773970362_49a49ba49a_o.png" alt="Dan Kaminskys personal website hacked" width="496" height="175" />
	<p class="wp-caption-text">Dan Kaminsky&#39;s personal website hacked</p>
</div>
<p>According to the note the hackers left on Dan&#8217;s website on doxpara.com/zf05.txt,</p>
<blockquote><p>We hacked Dan’s assets first through finding bugs and writing 0day, and then through abusing him giving away passwords and his silly password scheme. Check out just some of his passes: fuck.hackers, 0hn0z (root account on his mail box), fuck.omg, fuck.vps, ohhai</p>
<p>Five character root password? Niiiiiiice.</p>
<p>From .mysql_history:</p>
<p>SET PASSWORD FOR ‘root’@&#8217;localhost’ = PASSWORD(’fuck.mysql’);</p>
<p>See the pattern?</p></blockquote>
<p>The hackers also criticized Dan for using insecure blogging and hosting services that they used to host their websites and in turn allowing access to their personal data.</p>
<p>If you looked at Dan&#8217;s website, he used WordPress as his Content Management Solution and used the <a title="Dropshadow wordpress theme" href="http://www.briangardner.com/themes/dropshadow-wordpress-theme.htm" target="_blank">Dropshadow wordpress theme</a> developed by Brian Gardner.</p>
<div class="wp-caption alignnone" style="width: 500px">
	<img title="Dan Kaminsky using WordPress as his CMS" src="http://farm4.static.flickr.com/3472/3773970370_c7cd7f3b22.jpg" alt="Dan Kaminsky using WordPress as his CMS" width="500" height="44" />
	<p class="wp-caption-text">Dan Kaminsky using WordPress as his CMS</p>
</div>
<p>Looking at the theme, the last development occurred around April 2007. Could the hackers have used some vulnerability in the theme itself or did Dan have an insecure version of WordPress installed on his webserver? Either case, if you are using WordPress as your content management solution, it is important to think about <a title="WordPress security" href="http://www.root777.com/wordpress/wordpress-security-tips-to-protect-your-wordpress-blog/" target="_blank">WordPress security</a>.</p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=118&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/do-no-evil/dan-kaminsky-gets-hacked/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How to hide your email address from spammers, a thorough guide</title>
		<link>http://www.root777.com/security/how-to-hide-your-email-address-from-spammers-a-thorough-guide/</link>
		<comments>http://www.root777.com/security/how-to-hide-your-email-address-from-spammers-a-thorough-guide/#comments</comments>
		<pubDate>Thu, 18 Jan 2007 14:59:22 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Do no Evil!]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Spam]]></category>

		<guid isPermaLink="false">http://www.ajit1.com/2007/01/18/how-to-hide-your-email-address-from-spammers-a-thorough-guide/</guid>
		<description><![CDATA[Every IT professional worth his/her salt has their own webpage/blog these days. While you may have people from all over the globe dropping a line at your site, Email harvesters are the most unwanted visitors on any website. These email spambots crawl the web via search engines to find and extract email addresses from webpages. [...]]]></description>
			<content:encoded><![CDATA[<p></p><p align="justify"><!--fingerprint-->Every IT professional worth his/her salt has their own webpage/blog these days. While you may have people from all over the globe dropping a line at your site, Email harvesters are the most unwanted visitors on any website. These email spambots crawl the web via search engines to find and extract email addresses from webpages. E-mail addresses in your blog or webpage are no secret to spam robots. Here&#8217;s a guide that should help you protect your email addresses from these spam spiders. Techniques mentioned use text manipulation, Masking, HTML, Flash, CSS, and JS to hide email addresses.<br />
<strong>How email spammers operate?</strong> Email addresses always contain an @ symbol. Most spambots do a pattern-search for likely combinations of letters (abc@xyz.com) like billgates@microsoft.com or larrypage@google.org in the HTML source of webpages. Often they just search for the @ character and grab all the letters on each side on the assumption that it&#8217;s a valid email address.<br />
<strong>How to keep your email address available to humans but invisible to email spiders?</strong> There are tons of Email Address Protector software that claim to protect your email address in web pages and get rid of junk mail &#8211; Don&#8217;t waste your money, they only encode your email or generate a javascript snippet. We will discuss manual email encoding techniques here. If a visitor clicks an encryped email link on your website, it will work as normal, but spam robots will not be able to extract the address from the link.<span id="more-57"></span><br />
<strong>#1: Replace the AT (@) and DOT (.) symbols: </strong></p>
<p>The most common approach to block email harvesting is to remove the @ symbol. If you eliminate the @ from email addresses then most spambots won&#8217;t be able to recognize that the text is actually an email addresses: Here are some examples:<br />
ajit AT askstudent DOT com ajit (at) askstudent.com ajit@askstudent.com ajit_AT_askstudent_DOT_com<br />
<strong>#2: Mask your email with tags, append meaningful words:</strong></p>
<p>Consider &#8220;masking&#8221; your email address. Masking involves putting a word or phrase in your email address so that it will trick a harvesting computer program, but not a person. Some email masking examples commonly employed by newsgroups and mailing list subscribers:<br />
ajit@askstudent.com.nospam ajit@askstudent.com.removeme ajit@REMOVE.askstudent.com<br />
<strong>#3: Replace text with an image: </strong></p>
<p><img align="right" src="http://www.askstudent.com/emailimage.png" /> This technique involves creating a graphic or screen capture of your email address text in jpg, png or gif formats and display that picture instead of the actual address string. Robots and spiders can&#8217;t read the text that is embedded in the image. Anyone who wants to email you will have to manually type in your address though.<br />
<strong>#4: Email Obfuscators: </strong></p>
<p>E-mail Obfuscator make you email less vulnerable to spammers. Using an online email Obfuscator, convert (or disguise) individual characters of your email address into corresponding ASCII code (a &lt;=&gt; a hex coding) For example, the email address a@b.com is represented in ASCII as: a@b.com The above ASCII string can be used as arguement for mailto: HTML tag as shown here. Email addresses will appear perfectly normal, and will even be clickable, to human visitors to your website. <a href="mailto:ASCII_STRING">e-mail to confuse sniffer ASCII_STRING </a><br />
<strong>#5: Encode the mailto: and @ symbols with special HTML characters </strong><br />
Encode the mailto: and @ characters with this code: mailto: changes to mailto @ changes to @<br />
The email link HTML code to hide your email address will look like: &lt; a href=&#8221;mailtoname@domain.com&#8221; mce_href=&#8221;mailtoname@domain.com&#8221; &gt;hidden email&lt; /a&gt;<br />
<strong>Hide email using CSS trick (direction property)</strong><br />
Scramble the email &#8211; While coding HTML, jumble and write the email address in reverse direction. (a@b.com should be written as moc.b@a). We can then use CSS stylesheet to reverse the email address againwhen rendering. Here&#8217;s the sample HTML code with CSS. &lt; style type=&#8221;text/css&#8221;&gt; .backwards {unicode-bidi:bidi-override; direction: rtl;} &lt; /style&gt; &lt; span class=&#8221;backwards&#8221;&gt;moc.b@a&lt; /span&gt;</p>
<p>If someone copies your email address, it will available in the reverse direction. Would not work on older browsers.</p>
<p><strong>Use Macromedia Flash </strong>You can easily create a tiny.swf file in Flash with embedded mailto: behaviour. The button action used to pick up the text held in the variables is: on (release){ getURL (&#8220;mailto:&#8221; +recipient+ &#8220;?cc=&#8221; + cc + &#8220;&amp;subject=&#8221; + subject + &#8220;&amp;body=&#8221; +body) } Requires Macromedia Flash player on client&#8217;s machine.</p>
<p><strong><u>How to hide your email address from spammers with JavaScript</u></strong></p>
<p>Let&#8217;s look at more advanced methods that use javascipt to hide the email (name@domain.com). Remember to use noscript tags since some users prefer to disable javascript in browsers:</p>
<p><strong>1. Basic Email Script</strong><br />
<script language="JavaScript">    <!--  document.write("name" + "@" + "domain.com");  //--> </script></p>
<p><strong>2. Basic Mailto: Email Script with Link Text</strong></p>
<p><script language="JavaScript">    <!--  var user = "name";  var host = "domain.com";  var link = user + "@" + host;  document.write("<a hre" + "f=ma" + "ilto:" + user + "@" + host + ">" + link + "</a>");  //--> </script><strong>3. Inline JavaScript</strong><br />
<a href="http://www.askstudent.com/#" onclick="JavaScript:window.location='mailto:'+'name'+'@'+'domain'+'.com'">Send me an email</a></p>
<p><strong>4. External JavaScript file</strong></p>
<p><script src="http://www.askstudent.com/email-encoding.js" language="JavaScript"></script>The external javascript contains the code mentioned in 2 above.</p>
<p><strong>Enkoder Javscript Form </strong><br />
The enkoder form script generated an encrypted javascript as shown below:</p>
<p>Original HTML: <a href="mailto:user@example.com" title="mail me">write email</a><br />
Encrypted HTML code</p>
<p><textarea cols="55" rows="5" style="font-size: 9px; font-family: monaco, monospaced">&lt;script type=&#8221;text/javascript&#8221;&gt;/* &lt;![CDATA[ */function hivelogic_enkoder(){var kode="kode=\";)'':)1-htgnel.edok(tArahc.edok?htgnel.edok&lt;i(+x=edok})i(tArahc.edo"+"k+)1+i(tArahc.edok=+x{)2=+i;)1-htgnel.edok(&lt;i;0=i(rof;''=x;\\\")''n(oi.j()"+"seerev.r')('itpl.sdekoe=od;kk\\\"\\\\do=e\\\\\\\\\\\"\\\\kode\\\\\\\\\\\\"+"\\\\\\\\\\\\\\\"\\\\r=hn%gn@gr%h,__@_&gt;d%?_vAw2_wAh__%___hw__wv__%___o@l_#h"+"_w_w_%__r_1_oppf{hCshdxhruovd=_wpl__%___h@k_di_u?#__w+u%1hqlpzfwgh&gt;x%rn_gr"+"@hrnhgv1oswl*+,*u1yhuhhv,+m1lr+q**&gt;,@%*{i*u&gt;lr3+l@+&gt;r?hnogq1wh0j,kl4@&gt;,.{5"+"@~r.hnfgd1Dk+u.w,ln4g.1rkhufwdlD\\\\\\\\+\\\\\\\\\\\\\\\\,\\\\\\\\000nrgh@"+"{.+l?nrgh1ohqjwkBnrgh1fkduDw+nrgh1ohqjwk04,=**,&gt;\\\\\\\\;\\\"\\\\\\\\\\\\="+"\\\\\\\\'xf'r;io0(i=k;d&lt;.oeeglhnit+;{+=)ocekcda.ChdrAo(e)t3ii-(;&lt;f)c+01c8="+"x2=;t+iSgrfno.CramChdr(o)ekcd}=oxe\\\\\\\\\\\"\\\\x;'=;'of(r=i;0&lt;ik(do.eel"+"gnht1-;)+i2={)+xk=do.ehcratAi(1++)okedc.ahAr(t)ik}do=e+xi(k&lt;do.eelgnhtk?do"+".ehcratAk(do.eelgnht1-:)'';)=\\\"\\\\deko\\\"=edok\";kode=kode.split('').r"+"everse().join('')";var i,c,x;while(eval(kode));}hivelogic_enkoder();/* ]]&gt; */&lt;/script&gt;</textarea></p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=57&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/security/how-to-hide-your-email-address-from-spammers-a-thorough-guide/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Demonstration of Windows XP Privilege Escalation Exploit</title>
		<link>http://www.root777.com/security/demonstration-of-windows-xp-privilege-escalation-exploit/</link>
		<comments>http://www.root777.com/security/demonstration-of-windows-xp-privilege-escalation-exploit/#comments</comments>
		<pubDate>Fri, 12 Jan 2007 15:00:11 +0000</pubDate>
		<dc:creator>Ajit Gaddam</dc:creator>
				<category><![CDATA[Do no Evil!]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ajit1.com/2007/01/12/demonstration-of-windows-xp-privilege-escalation-exploit/</guid>
		<description><![CDATA[This article is not a hacking tutorial. This is only to be used for educational purposes and should not be exploited. Using simple command line tools on a machine running Windows XP, we will obtain system level priviledges. The system run level is higher than administrator, and has full control of the operating system and it’s [...]]]></description>
			<content:encoded><![CDATA[<p></p><p><!--fingerprint--><u><em>This article is not a hacking tutorial. This is only to be used for educational purposes and should not be exploited.</em></u></p>
<p>Using simple command line tools on a machine running Windows XP, we will obtain system level priviledges. The system run level is higher than administrator, and has full control of the operating system and it’s kernel. On many machines this can be exploited even with the guest account. This system account allows for several other things that aren’t normally possible (like resetting the administrator password).<br />
The Local System account is used by the Windows OS to control various aspects of the system (kernel, services, etc); the account shows up as SYSTEM in the Task Manager process list, as seen in the following screen shot:<br />
Local System differs from an Administrator account in that it has full control of the operating system, similar to root on a *nix machine. Most System processes are required by the operating system, and cannot be closed, even by an Administrator account; attempting to close them will result in a error message.</p>
<p>The following quote from Wikipedia explains this in a easy to understand way:</p>
<blockquote><p>: <em>In Windows NT and later systems derived from it (Windows 2000, Windows XP, Windows Server 2003 and Windows Vista), there may or may not be a superuser. By default, there is a superuser named Administrator, although it is not an exact analogue of the Unix root superuser account. Administrator does not have all the privileges of root because some superuser privileges are assigned to the Local System account in Windows NT. </em></p></blockquote>
<p>Under normal circumstances, a user cannot run code as System, only the operating system itself has this ability, but by using the command line, we will trick Windows into running our desktop as System, along with all applications that are started from within. <strong> </strong> <strong>Procedure to get system level access and previlege escalation in </strong><strong>windows </strong>I will now walk you through the process of obtaining <strong>SYSTEM</strong> privileges and a demonstration of this Windows XP admin exploit / super user hack </p>
<p align="justify"><span id="more-51"></span></p>
<p>To start, lets open up a command prompt (Start &gt; Run &gt; cmd &gt; [ENTER]).</p>
<p>At the prompt, enter the following command, then press [ENTER]:</p>
<table width="90%" cellPadding="3" cellSpacing="1" style="text-align: center">
<tr>
<td><span class="genmed"><strong>Code:</strong></span></td>
</tr>
<tr>
<td class="code">at</td>
</tr>
</table>
<p>If it responds with an “access denied” error, then we are out of luck, and you’ll have to try another method of privilege escalation; if it responds with “There are no entries in the list” (or sometimes with multiple entries already in the list) then we are good. Access to the at command varies, on some installations of Windows, even the Guest account can access it, on others it’s limited to Administrator accounts. If you can use the at command, enter the following commands, then press [ENTER]:  </p>
<table width="90%" cellPadding="3" cellSpacing="1" style="text-align: center">
<tr>
<td><span class="genmed"><strong>Code:</strong></span></td>
</tr>
<tr>
<td class="code">at 21:01 /interactive “cmd.exe”</td>
</tr>
</table>
<p><span class="postbody"><span class="postbody">Lets break down the preceding code. The “at” told the machine to run the at command, everything after that are the operators for the command, the important thing here, is to change the time (24 hour format) to one minute after the time currently set on your computers clock, for example: If your computer’s clock says it’s 4:30pm, convert this to 24 hour format (16:30) then use 16:31 as the time in the command. If you issue the <strong>at</strong> command again with no operators, then you should see something similar to this:<br />
</span><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"></span></span></span></span><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"></span></span></span></span></span></span><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"></span></span></span></span></span></span><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"><center><br />
<img src="http://i111.photobucket.com/albums/n150/askstudent/winxpex1.png" /><br />
</center>    When the system clock reaches the time you set, then a new command prompt will magically run. The difference is that this one is running with system privileges (because it was started by the task scheduler service, which runs under the Local System account). It should look like this: <br />
<img src="http://i111.photobucket.com/albums/n150/askstudent/winxpex2.png" /><br />
  </p>
<p>You’ll notice that the title bar has changed from cmd.exe to svchost.exe (which is short for Service Host). Now that we have our system command prompt, you may close the old one. Run Task Manager by either pressing CTRL+ALT+DELETE or typing taskmgr at the command prompt. In task manager, go to the processes tab, and kill explorer.exe; your desktop and all open folders should disappear, but the system command prompt should still be there.</p>
<p align="justify">At the system command prompt, enter in the following:</p>
<p align="justify">&nbsp;</p>
<p></span></p>
<p align="justify">
<table width="90%" cellPadding="3" cellSpacing="1" style="text-align: center">
<tr>
<td><span class="genmed"><strong>Code:</strong></span></td>
</tr>
<tr>
<td class="code">explorer.exe</td>
</tr>
</table>
<p align="justify"><span class="postbody"><span class="postbody">A desktop will come back up, but what this? It isn’t your desktop. Go to the start menu and look at the user name, it should say “SYSTEM”. Also open up task manager again, and you’ll notice that explorer.exe is now running as SYSTEM. The easiest way to get back into your own desktop, is to log out and then log back in.<br />
</span><span class="postbody"><span class="postbody"><span class="postbody"><span class="postbody"><center><br />
<a target="_blank" href="http://i111.photobucket.com/albums/n150/askstudent/winxpex3.png"><img src="http://i111.photobucket.com/albums/n150/askstudent/winxpex3.png" /></a><br />
Now that we have <strong>SYSTEM</strong> access, everything that we run from our explorer process will have it too, browsers, games, etc. You also have the ability to reset the administrators password, and kill other processes owned by <strong>SYSTEM</strong>. You can do anything on the machine, the equivalent of root; You are now God of the Windows machine. I’ll leave the rest up to your imagination.<br />
<center><br />
<a target="_blank" href="http://i111.photobucket.com/albums/n150/askstudent/winxpex4.png"><img src="http://i111.photobucket.com/albums/n150/askstudent/winxpex4.png" /></a><br />
<em>Resetting Administrator’s password</em></center></center></span></span></span></span></span></p>
<p></span></span></span></span></span></p>
<img src="http://www.root777.com/?ak_action=api_record_view&id=51&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.root777.com/security/demonstration-of-windows-xp-privilege-escalation-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.674 seconds -->
