hacking security forum

[Full-Disclosure] Get admin rights using Doro (pdf creator)

From: Ramon Kukla <ml@portsonline.net>
Date: Sun Dec 14 2003 - 15:04:41 CST

Hi,

a few days ago i discovered a bug in Doro. Doro is a free tool to
create pdf files from any windows program. After installing Doro you
have a new printer called 'Doro PDF Writer'.
If you select 'Print' the spooler calls the printer filter 'doro.dll'.
The 'doro.dll' then starts 'doro.exe' and a file requester appears.

I guess that most of you see the problem. The spooler is controlled by
the account 'system'. Therefore the file requester has the same rights.

It's easy now to create a new user and move them into the group
'admins'.

I informed the coder of the software and he approved the problem.

regards
Ramon

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Sun Dec 14 15:25:28 2003

This archive was generated by hypermail 2.1.8 : Sun Dec 14 2003 - 16:01:01 CST

Custom Search