phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, please share.


Wireshark 1.10.0rc2 is now available http://www.wireshark.org/download.html
Chrome 24.0.1312.52 has been updated for Windows, Mac, Linux, and Chrome Frame
Apple QuickTime 7.7.4 for Windows updated, MANY security vulnerabilities: http://support.apple.com/kb/HT1222
Wireshark 1.8.7 and 1.6.15 Released http://www.wireshark.org/news/20130517.html

advertisement
Diary Advertisement

Use Discount Code SANSFIREISC10 when registering to get a 10% discount!!

Privilege escalation, why should I care?

Published: 2013-05-22,
Last Updated: 2013-05-22 16:10:59 UTC
by Adrien de Beaupre (Version: 1)

13 comment(s)

In my day job I spend about 90% of my time on the red team, performing vulnerability assessment and penetration testing. The rest is spent on threat research, incident response, and digital forensics. Interacting with clients as a consultant I often hear what I term 'interesting' responses. When a penetration tester calls something interesting you should probably pay attention :)

The IDS only listens external to the firewall? SharePoint is directly exposed to the Internet? The WAF protects against attacks therefore we don't have to fix the application? The VMs are all physically on the same host? The DMZ and the internal VLAN are physically on the same switch? You don't bother with privilege escalation patches? All quite interesting.

One of the responses I have heard multiple times is that privilege escalation vulnerabilities are a low priority because they require the attacker have local access. Meaning that that would be very difficult to pull off, therefore we don't have to worry about it. This also assumes that every single account holder is 100% gruntled all of the time, and that nobody ever makes a mistake. Meaning that we can trust everyone who accesses our networks and applications. Which I also find to be 'interesting' :)

There are multiple types of privilege attacks. The first is privilege escalation, where someone who has valid credentials or means to access a network or application can raise their level of access to a more privileged level. Like getting root on a Unix system for example, or becoming Domain admin before lunch on day 1, or assuming a higher role within an application. Impersonation attacks are similar however they entail becoming a different user, often with the same level of privilege, but with way more money in their account :) which soon finds its way to a non-extradition treaty country.

If the major difference between a remote exploit and a local one is that a network connection is required for the former, and not for the latter, does this mean that local priv escalation attacks cannot be performed across the network? Actually no. If an attacker can gain access to a system through a client side exploit, they may then effectively become the local user, and escalate to local system. Local system priv on a Windows computer is just a hop, skip, and jump away from being Domain administrator.

In a recent discussion about the priority to be assigned to patch one comment was "It's only a privilege escalation!". Yes, you are correct, and that is an interesting statement was my response.

Cheers,
Adrien de Beaupré
Intru-shun.ca Inc.
My SANS Teaching Schedule

13 comment(s)
ISC StormCast for Wednesday, May 22nd 2013 http://isc.sans.edu/podcastdetail.html?id=3323

If you have more information or corrections regarding our diary, please share.

Diary Archive

DateAuthorTitle
2013-05-22 Adrien de Beaupre Privilege escalation, why should I care? (13 Comments)
2013-05-21 Adrien de Beaupre Moore, Oklahoma tornado charitable organization scams, malware, and phishing (0 Comments)
2013-05-20 Guy Bruneau Safe - Tools, Tactics and Techniques (0 Comments)
2013-05-20 Johannes Ullrich Ubuntu Package available to submit firewall logs to DShield (3 Comments)
2013-05-19 Kevin Shortt Port 51616 - Got Packets? (1 Comments)
2013-05-17 Daniel Wesemann e-netprotections.su ? (3 Comments)
2013-05-17 Johannes Ullrich SSL: Another reason not to ignore IPv6 (3 Comments)
2013-05-16 Joel Esler Cisco TelePresence Supervisor MSE 8050 Denial of Service Vulnerability (1 Comments)
2013-05-16 Daniel Wesemann Extracting signatures from Apple .apps (0 Comments)
2013-05-15 Joel Esler Call for Papers - 4th annual Forensics and Incident Response Summit EU (0 Comments)
Folder Icon Complete Archive
Search Diaries:

Diary Tagslink arrow

  got packets     fantasia     patch     rfc6555     ubuntu     thunderbird     email     ipv6 focus month     spamhaus     signature     blackhole     cve20120158     bgp     trojan     java     remnux     boston marathon explosions     61     notification     postgresql     tornado     cisco     patches     kernel     scam     malware     apple     spoofing     anti virus     linux     0 day     ie 8     certificates     denial of service     fake charities     cyberbunker     firewall     java 7u21     usbexe     microsoft     cloudflare     mt6d     boston marathon     port 51616     ddos     psexec     sourcefire     oklahoma     ipv4     perimeter     enterprise certificate authority     dshield     bcp 38     phishing     snort     boston marathon bombing     vrt     patch tuesday     overview     java security update     vulnerability     micorsoft     outage     internet status     cyberterrorism     mozilla     opendoc     black tuesday     ssl     passwords     msft     51616     typo squatting     back tuesday     waco fertilizer plant explosion     flash     apache     usbdoc     disaster     fake tech calls     javascript     phish     security intelligence     privilege escalation     sysinternals     exploit     gov     packets     ipv6     ios     firefox     charity     webserver     xss     malware containment     configuration     security advisory     preference     certutil     advance notification     happy eyeballs     protocol     java vulnerability     chargen     adobe     cnn     certificate     malware analysis     watering hole     relays     spam     rfc6724     dos     boston marathon scams     frequency hopping     hak5     safe     updates     incident     google     tools     web app sec  
site/port/ip search:

Announcement!

IPv6 Support Added

Our iptables client now supports submitting IPv6 firewall logs.

ISC Polllink arrow

What are your plans when XP is no longer supported?

World Map

world map

Trends

trend graph
footer-->