Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Not a Security Boundary - Bypassing User Account Control

via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of User Account Control (UAC) and its vulnerabilities in this 49-minute conference talk from Derbycon 7. Delve into the concept of UAC as a non-security boundary, understanding integrity levels and the security reference monitor. Examine bypass research techniques, including registry manipulation and file operations. Learn about the AlwaysNotify bypass and its associated PowerShell script. Gain insights into potential mitigations and use this talk as a starting point for further exploration of UAC security implications.

Syllabus

Intro
Presentation Overview
What is UAC
Not a security boundary
Integrity level
Security reference monitor
AlwaysNotify
Default isNotify
Bypass Research
The Ideal Situation
Process Monitor
Registry Manipulation
Other Primitives
Old IFile Operation
Registry Verb Handling Modification
John Lambert
Event Viewer
AlwaysNotify Bypass
PowerShell Script
Original POC
Mitigation
Starting Point

Reviews

Start your review of Not a Security Boundary - Bypassing User Account Control

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.