Hi all, I was thinking about the possibility to fake the UAC prompt for credentials by a malicious process, in order to get the admin password. In example, a malicious process shows a fake UAC dialog prompting for Admin credentials when started, and then stores the admin password for later sending or wathever. Since Vista shows too many UAC dialogs, I think we will enter the admin credentials in a mechanichal way, so this exploit could be possible and easy to implement. I'm missing some important technichal data about UAC which prevents this? What do you think?
Fernando

(Semi OT) UAC exploit possible via fake dialogs?
I read somewhere the UAC will be a bit less intrusive in the future.. but I thinkif some program did want to put up a "fake" UAC you'd still have to give it permission to run.. and then it would also run into the Firewall later on assuming you have that enabled also.
"Fernando" wrote:
Hi all, I was thinking about the possibility to fake the UAC prompt for credentials by a malicious process, in order to get the admin password. In example, a malicious process shows a fake UAC dialog prompting for Admin credentials when started, and then stores the admin password for later sending or wathever. Since Vista shows too many UAC dialogs, I think we will enter the admin credentials in a mechanichal way, so this exploit could be possible and easy to implement. I'm missing some important technichal data about UAC which prevents this? What do you think?
Fernando
Think the following: If I put on a system a custom made executable which on run shows a fake UAC dialog and it doesn't requires privileged credentials to run, the true UAC never shows, and if this executable never connects to the outside and only stores admin passwords on file, in example, to allow later retrieval, it also never gets the firewall prompt. Think about a lot of people, normal Windows users, which never complains about security, then may be it will be a serious security problem.
"Jason" wrote in message
I read somewhere the UAC will be a bit less intrusive in the future.. but I thinkif some program did want to put up a "fake" UAC you'd still have to give it permission to run.. and then it would also run into the Firewall later on assuming you have that enabled also.
"Fernando" wrote:
Hi all, I was thinking about the possibility to fake the UAC prompt for credentials by a malicious process, in order to get the admin password. In example, a malicious process shows a fake UAC dialog prompting for Admin credentials when started, and then stores the admin password for later sending or wathever. Since Vista shows too many UAC dialogs, I think we will enter the admin credentials in a mechanichal way, so this exploit could be possible and easy to implement. I'm missing some important technichal data about UAC which prevents this? What do you think?
Fernando
Windows Vista
User login
Related topics
- Lexmark X3350 All in One
- Virtual Server 2005 R2 is FREE!
- installer error:
- Quicken Online Broken
- Upgrade hangs when trying to Upgrade from XP to Vista
- Windows Vista embeded (scanner/printer/digital camera) drive
- BitLocker key change question
- same problem with jrigby
- Unable to use windows explorer
- AH Vista through Virtual PC 2004 -- unknown device
- General Access Denied Error
- (80070017
- Silent failure installing VS2005 on 64bit 5308
- Do you Use Aero Glass?
- Errors During Installation
- HP TC1100 weird headphone problem
- Problems register Dll's
- nforce 3 sata raid installation issues
- Beta Keys
- CRC checker?
- Santa Cruz sound card
- LG DVD Drives
- PHP
- Mobile Device center wizzard can't skip exchange
- Flight Sim 2004
- NVIDIA GeForce FX 5200 not compatible with VGA??
- back screen install issue
- XP hard drive as a slave
- Vista CTP 5308 Install
- Internet Explorer 7 from Windows Vista 5384
- Fast User Switching
- 80070017 Error code Resolution
- error code 80000000
- cant instal windows!!!
- Another case of "Black Screen" woes
- Fx5200 on KM4M - video severely corrupt
- local administrator account password = ?