<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Martin Zugec blog : Security</title><link>http://msmvps.com/blogs/martinzugec/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Elevator - command line</title><link>http://msmvps.com/blogs/martinzugec/archive/2008/05/19/elevator-command-line.aspx</link><pubDate>Mon, 19 May 2008 15:15:39 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1624362</guid><dc:creator>martin</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/rsscomments.aspx?PostID=1624362</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/commentapi.aspx?PostID=1624362</wfw:comment><comments>http://msmvps.com/blogs/martinzugec/archive/2008/05/19/elevator-command-line.aspx#comments</comments><description>&lt;p&gt;If you tried &lt;a href="http://msmvps.com/blogs/martinzugec/archive/2008/05/16/ignore-uac-for-specific-programs.aspx" target="_blank"&gt;elevator&lt;/a&gt;, you probably know that it is running thought context menu:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/blogs/martinzugec/WindowsLiveWriter/Elevatorcommandline_F186/image_2.png"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" border="0" alt="image" src="http://msmvps.com/blogs/martinzugec/WindowsLiveWriter/Elevatorcommandline_F186/image_thumb.png" width="244" height="168" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;It is assigned only to exe files (if it is needed, I can extend it)... But sometimes you may want to change shortcut to &lt;strong&gt;always &lt;/strong&gt;run specific action using elevator.&lt;/p&gt; &lt;p&gt;In fact it is pretty easy - just run ElevatorRunner.exe with filename and parameters and you are all set :)&lt;/p&gt; &lt;p&gt;First parameter is executable you want to run and then any command line arguments you want to include. &lt;/p&gt; &lt;p&gt;For example if you want to elevate MMC.exe, simply runs &lt;em&gt;ElevatorRunner MMC.exe&lt;/em&gt; and thats it. &lt;/p&gt; &lt;p&gt;&lt;br /&gt;To also show example with command line parameters, this is command line I use to run Joost:&lt;br /&gt;&lt;em&gt;C:\Data\SkipUAC\ElevatorRunner.exe &amp;quot;C:\Program Files (x86)\Joost\xulrunner\tvprunner.exe&amp;quot; &amp;quot;C:\Program Files (x86)\Joost\application.ini&amp;quot;&lt;/em&gt;&lt;/p&gt; &lt;p&gt;&lt;em&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;In following screenshot you can see few examples:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/blogs/martinzugec/WindowsLiveWriter/Elevatorcommandline_F186/image_6.png"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" border="0" alt="image" src="http://msmvps.com/blogs/martinzugec/WindowsLiveWriter/Elevatorcommandline_F186/image_thumb_2.png" width="244" height="125" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;It is also pretty easy to modify shortcuts to use Elevator:&lt;/p&gt; &lt;p&gt;&lt;a href="http://msmvps.com/blogs/martinzugec/WindowsLiveWriter/Elevatorcommandline_F186/image_8.png"&gt;&lt;img style="border-right:0px;border-top:0px;border-left:0px;border-bottom:0px;" border="0" alt="image" src="http://msmvps.com/blogs/martinzugec/WindowsLiveWriter/Elevatorcommandline_F186/image_thumb_3.png" width="174" height="244" /&gt;&lt;/a&gt; &lt;/p&gt; &lt;p&gt;Martin&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1624362" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Development/default.aspx">Development</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Utilities/default.aspx">Utilities</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Tips_2600_amp_3B00_Tricks/default.aspx">Tips&amp;amp;Tricks</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Vista/default.aspx">Vista</category></item><item><title>Leet haxor?</title><link>http://msmvps.com/blogs/martinzugec/archive/2008/02/22/leet-haxor.aspx</link><pubDate>Fri, 22 Feb 2008 19:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1521928</guid><dc:creator>martin</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/rsscomments.aspx?PostID=1521928</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/commentapi.aspx?PostID=1521928</wfw:comment><comments>http://msmvps.com/blogs/martinzugec/archive/2008/02/22/leet-haxor.aspx#comments</comments><description>&lt;p&gt;Few days ago I posted&amp;nbsp;small &lt;a class="" title="blog entry" href="http://msmvps.com/blogs/martinzugec/archive/2008/02/19/how-to-control-google-using-keyboard.aspx" target="_blank"&gt;blog entry&lt;/a&gt;&amp;nbsp;about using keyboard for navigating on Google - it is in fact quite old, I tried it few months ago, but few days ago I started to really use it and I found it quite usefull, so I wanted to share... &lt;/p&gt;
&lt;p&gt;Today I received new comment (well, it was not published automatically and I received mail that there appears to be some spam in comments). &lt;/p&gt;
&lt;p&gt;I read that comment - and that again and again, just to be sure that I am not missing something:&lt;/p&gt;
&lt;p&gt;&amp;quot;u suck at hacking, i am able to control live webcmas using google, and also change wats on while tv is on, dont beleive me, than screw u, if this was supposed to be a hack, u suck, leave my hacking territory, because when u mess with the best, u will die like the rest!&amp;quot;&lt;/p&gt;
&lt;p&gt;I am still not sure if I should smile or cry (well, or be scared that he could change my TV through Google :D)&lt;/p&gt;
&lt;p&gt;Well, to make this post at least little bit useful: nice trick regarding that Google keyboard shortcuts is that if you are on last entry and you press J (go to next result), it will automatically go to next page (and that is maybe most useful function of that nice Google feature that you can read few pages of results pretty quickly)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1521928" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Fun/default.aspx">Fun</category></item><item><title>How to view restricted web pages</title><link>http://msmvps.com/blogs/martinzugec/archive/2007/12/10/how-to-view-restricted-web-pages.aspx</link><pubDate>Mon, 10 Dec 2007 19:42:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1390838</guid><dc:creator>martin</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/rsscomments.aspx?PostID=1390838</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/commentapi.aspx?PostID=1390838</wfw:comment><comments>http://msmvps.com/blogs/martinzugec/archive/2007/12/10/how-to-view-restricted-web-pages.aspx#comments</comments><description>&lt;p&gt;Well, it happens sometimes that certain web pages are blocked even if they are not dangerous at all and contains tools you really must have to fix something... For example it is quite hard to get some *nix tools like netcat usually :(&lt;/p&gt;
&lt;p&gt;There are few techniques how to access such restricted pages - because I am not accessing these pages regularly, but it sometimes happens, I added &amp;quot;Access restricted&amp;quot; search provider to my IE7...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;How to do it?&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;div&gt;Go to&amp;nbsp;&lt;a href="http://www.microsoft.com/windows/ie/searchguide/en-en/default.mspx"&gt;http://www.microsoft.com/windows/ie/searchguide/en-en/default.mspx&lt;/a&gt;#&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Paste URL &lt;a href="http://www.google.com/translate?langpair=es|en&amp;amp;u=TEST"&gt;http://www.google.com/translate?langpair=es|en&amp;amp;u=TEST&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Name it as you want (mine is Access restricted)&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;Click on Install&lt;/div&gt;&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;In search providers, new provider appears that you can use to access restricted sites. &lt;/p&gt;
&lt;p&gt;P.S.: I know about anonymous proxies, however they are usually also blocked ;)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1390838" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Security/default.aspx">Security</category></item><item><title>Good bye, "Click to activate" ActiveX</title><link>http://msmvps.com/blogs/martinzugec/archive/2007/11/13/good-bye-quot-click-to-activate-quot-activex.aspx</link><pubDate>Tue, 13 Nov 2007 22:39:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1307756</guid><dc:creator>martin</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/rsscomments.aspx?PostID=1307756</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/commentapi.aspx?PostID=1307756</wfw:comment><comments>http://msmvps.com/blogs/martinzugec/archive/2007/11/13/good-bye-quot-click-to-activate-quot-activex.aspx#comments</comments><description>&lt;p&gt;Hooooray, great news :)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;Maybe you remember when Microsoft lost his case with Eolas, we were force to click on every #$%#@ ActiveX component on every web page - I don&amp;#39;t want to blame Microsoft for this, I don&amp;#39;t want to blame Eolas and definitely I don&amp;#39;t want to blame lawyers (because I got one at home ;))... &lt;/p&gt;
&lt;p&gt;But soon we will finally forget those dark times - Microsoft licensed that &amp;quot;technology&amp;quot; from Eolas - so soon we will get back our wonderfull old-style ActiveX processing :)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;To be more specific - December 2007 will be avaible patch preview and patch itself should be delivered at end of April 2008... &lt;/p&gt;
&lt;p&gt;&amp;nbsp;Want more details? Follow &lt;a href="http://blogs.msdn.com/ie/archive/2007/11/08/ie-automatic-component-activation-changes-to-ie-activex-update.aspx"&gt;http://blogs.msdn.com/ie/archive/2007/11/08/ie-automatic-component-activation-changes-to-ie-activex-update.aspx&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1307756" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Law/default.aspx">Law</category></item><item><title>Hacking SAM database on offline Windows </title><link>http://msmvps.com/blogs/martinzugec/archive/2007/05/23/hacking-sam-database-on-offline-windows.aspx</link><pubDate>Wed, 23 May 2007 21:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:922054</guid><dc:creator>martin</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/rsscomments.aspx?PostID=922054</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/commentapi.aspx?PostID=922054</wfw:comment><comments>http://msmvps.com/blogs/martinzugec/archive/2007/05/23/hacking-sam-database-on-offline-windows.aspx#comments</comments><description>&lt;p&gt;Today I had presentation for my colleagues - they had to prepare few vmware machines for me to test some functionalities...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;However there was old local administrator password on these boxes - the one that no one was able to remember...&lt;/p&gt;
&lt;p&gt;&amp;nbsp;So I tried to use one of my &amp;quot;oldies goldies&amp;quot; tools called Offline NT Password &amp;amp; Registry Editor. This utility (or should I say Linux distro? ;)) is using known security issues of windows with local SAM file (hope so it is fixed once and for all in Windows Vista). &lt;/p&gt;
&lt;p&gt;&amp;nbsp;You can download it here: &lt;a href="http://home.eunet.no/pnordahl/ntpasswd/"&gt;http://home.eunet.no/pnordahl/ntpasswd/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;You download CD image (you can burn it or mount it to virtual CD drive), boot from it, hit enter few times (default configuration) and voila - you local administrator password is empty - and you were able to do it in few minutes....&lt;/p&gt;
&lt;p&gt;&amp;nbsp;I know that I shouldnt be happy about such security bug (specially if even SysKey is not able to protect you), however it helped me too many times... And hope so it will help you too :)&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=922054" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Security/default.aspx">Security</category></item><item><title>Security issue with PowerShell</title><link>http://msmvps.com/blogs/martinzugec/archive/2007/01/25/security-issue-with-powershell.aspx</link><pubDate>Thu, 25 Jan 2007 08:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:518156</guid><dc:creator>martin</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/rsscomments.aspx?PostID=518156</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/martinzugec/commentapi.aspx?PostID=518156</wfw:comment><comments>http://msmvps.com/blogs/martinzugec/archive/2007/01/25/security-issue-with-powershell.aspx#comments</comments><description>&lt;p&gt;Hi guys, &lt;/p&gt;
&lt;p&gt;&amp;nbsp;after (too) long time I can finally return to Powershell (I spend few months creating batch framework to manage citrix servers, right now it is about 980 scripts). &lt;/p&gt;
&lt;p&gt;I was playing with Get-Credential:&lt;/p&gt;
&lt;p&gt;$Operator = get-credential&lt;/p&gt;
&lt;p&gt;I provided my username/password. If I have a look at object, I can see Password property and GetPassword() method. I tried this, Output is in System.Security.SecureString.&lt;/p&gt;
&lt;p&gt;I was just thinking how PowerShell is handling explicit authentication, so I had a look at available properties and methods - GetNetworkCredential grab my eye, so I tried it. And I was really surprised by output:&lt;/p&gt;
&lt;p&gt;mzugec&amp;gt;$operator.GetNetworkCredential()&lt;/p&gt;
&lt;p&gt;UserName&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain&lt;br /&gt;--------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;--------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ------&lt;br /&gt;mzugec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YouPwdInPlainText&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MyDomain&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Replace YouPwdInPlainText with your actual password! So be aware, if you are using get-credentials, it is very easy to retrieve your actual password!&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=518156" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Scripting/default.aspx">Scripting</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Monad/default.aspx">Monad</category><category domain="http://msmvps.com/blogs/martinzugec/archive/tags/Security/default.aspx">Security</category></item></channel></rss>