what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

carboncopy.txt

carboncopy.txt
Posted Oct 27, 2004
Authored by Kevin Finisterre

Altiris Carbon Copy Version 6.0.5257 allows for a user to browse to cmd.exe and spawn a shell as SYSTEM.

tags | exploit, shell
SHA-256 | 6ef1b88164c9c818f8c4aa86dabcd881831325a0099d0eb3250d14e927fb9c7d

carboncopy.txt

Change Mirror Download
The only reason this was never disclosed was originally in hopes of 
proper vendor response... I spoke to their tech support about 5 times
but they were just total morons. I eventually gave up.

I was going to write a shatter like attack so this could be exploited
ala .exe file but I never had time.

Tested on Carbon Copy Version 6.0.5257

Start the Carbon Copy Service...
CCSRVC.exe is running as SYSTEM.

In the task bar you should see a little blue and white CC icon. Right
click on it and choose show user interface. CCW32.exe will then be
started with SYSTEM rights.

Choose help then "carbon copy help topics"... right click on the right
hand side of the help pane and choose "view source". You should get
notepad.exe running as SYSTEM. Click File then open... browse to cmd.exe
right click and open it.

Now you have local SYSTEM


Carbon Copy Scheduler at one point in time had its own service as well
so it could also be used to take SYSTEM... CCSched.exe runs as SYSTEM.
The schedulers help button can be used to take SYSTEM. The Add button
will take you to an other screen with a browse button that can be used...

Several variations of this span the products various versions. The
latest version I used did not contain the Scheduler Service...

I will eventually write up a proper advisory for this and an exploit
but... like I stated above... just been too busy to write the exploit.

Enjoy.

-KF


Brooks, Shane wrote:
> Can you elaborate a bit on the privilege escalation that you mentioned? If the hole has indeed been there over a year, why not disclose it publicy? Does anyone else have any info on Altiris vulnerabilities?
>

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    21 Files
  • 17
    Sep 17th
    51 Files
  • 18
    Sep 18th
    23 Files
  • 19
    Sep 19th
    48 Files
  • 20
    Sep 20th
    36 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close