Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

(Semi OT) UAC exploit possible via fake dialogs?

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 06-16-2006   #1 (permalink)
Fernando
Guest


 

(Semi OT) UAC exploit possible via fake dialogs?

Hi all,
I was thinking about the possibility to fake the UAC prompt for
credentials by a malicious process, in order to get the admin password.
In example, a malicious process shows a fake UAC dialog prompting for
Admin credentials when started, and then stores the admin password for
later sending or wathever. Since Vista shows too many UAC dialogs, I
think we will enter the admin credentials in a mechanichal way, so this
exploit could be possible and easy to implement.
I'm missing some important technichal data about UAC which prevents
this? What do you think?

Fernando

My System SpecsSystem Spec
Old 06-16-2006   #2 (permalink)
Jason
Guest


 

RE: (Semi OT) UAC exploit possible via fake dialogs?

I read somewhere the UAC will be a bit less intrusive in the future.. but I
thinkif some program did want to put up a "fake" UAC you'd still have to give
it permission to run.. and then it would also run into the Firewall later on
assuming you have that enabled also.

"Fernando" wrote:

> Hi all,
> I was thinking about the possibility to fake the UAC prompt for
> credentials by a malicious process, in order to get the admin password.
> In example, a malicious process shows a fake UAC dialog prompting for
> Admin credentials when started, and then stores the admin password for
> later sending or wathever. Since Vista shows too many UAC dialogs, I
> think we will enter the admin credentials in a mechanichal way, so this
> exploit could be possible and easy to implement.
> I'm missing some important technichal data about UAC which prevents
> this? What do you think?
>
> Fernando
>

My System SpecsSystem Spec
Old 06-17-2006   #3 (permalink)
Fernando
Guest


 

Re: (Semi OT) UAC exploit possible via fake dialogs?

Think the following: If I put on a system a custom made executable which on
run shows a fake UAC dialog and it doesn't requires privileged credentials
to run, the true UAC never shows, and if this executable never connects to
the outside and only stores admin passwords on file, in example, to allow
later retrieval, it also never gets the firewall prompt. Think about a lot
of people, normal Windows users, which never complains about security, then
may be it will be a serious security problem.


"Jason" <Jason@discussions.microsoft.com> wrote in message
news:8CD1694A-72CD-41E9-8D5C-DF2ECDD66C31@microsoft.com...
>I read somewhere the UAC will be a bit less intrusive in the future.. but I
> thinkif some program did want to put up a "fake" UAC you'd still have to
> give
> it permission to run.. and then it would also run into the Firewall later
> on
> assuming you have that enabled also.
>
> "Fernando" wrote:
>
>> Hi all,
>> I was thinking about the possibility to fake the UAC prompt for
>> credentials by a malicious process, in order to get the admin password.
>> In example, a malicious process shows a fake UAC dialog prompting for
>> Admin credentials when started, and then stores the admin password for
>> later sending or wathever. Since Vista shows too many UAC dialogs, I
>> think we will enter the admin credentials in a mechanichal way, so this
>> exploit could be possible and easy to implement.
>> I'm missing some important technichal data about UAC which prevents
>> this? What do you think?
>>
>> Fernando
>>


My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
semi-locked Greg Vista General 3 01-29-2008 08:14 AM
WGA says Fake - Win Diagnostics says Genuine????? Dave Thomas Vista General 5 08-08-2007 05:34 PM
semi-modal dialog box vikram.nayak@gmail.com Avalon 1 06-29-2007 02:58 PM
Language bar keeps semi-resetting Y Vista General 0 03-21-2007 08:21 PM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51