<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msinfluentials.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Mitigate the Image Uploader Vulnerabilities</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/02/06/mitigate-the-image-uploader-vulnerabilities.aspx</link><description>The big security news this week is the six vulnerabilities found in various image uploader ActiveX controls. In case you haven&amp;#39;t seen the news , there are exploits available publicly for remote vulnerabilities in five different ActiveX controls. US</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>re: Mitigate the Image Uploader Vulnerabilities</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/02/06/mitigate-the-image-uploader-vulnerabilities.aspx#7430</link><pubDate>Fri, 15 Feb 2008 07:04:45 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:7430</guid><dc:creator>Anthony Perkins</dc:creator><description>&lt;p&gt;Jesper, thanks for your work on this.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=7430" width="1" height="1"&gt;</description></item><item><title>re: Mitigate the Image Uploader Vulnerabilities</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/02/06/mitigate-the-image-uploader-vulnerabilities.aspx#7427</link><pubDate>Thu, 14 Feb 2008 16:39:17 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:7427</guid><dc:creator>Roshan James</dc:creator><description>&lt;p&gt;Sorry for a comment that is a little out of place. What brings me to your website is your article about ACLs and such. &lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/technet/community/columns/secmgmt/sm1105.mspx"&gt;www.microsoft.com/.../sm1105.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There you say strange things like this:&lt;/p&gt;
&lt;p&gt;&amp;quot;Power Users are administrators who simply have not made themselves administrators yet.&lt;/p&gt;
&lt;p&gt;You cannot remove the ACLs on the file system, or even the registry, and prevent that. Power Users are ingrained in the operating system, and they have sufficient privileges to escalate to an administrator fairly easily.&amp;quot;&lt;/p&gt;
&lt;p&gt;At the risk of sounding obnoxious I must say, I am baffled by how anyone is expected to know this. Is there some place where this is all written down is a accessible way? Maybe a lattice of builtin users and a lattice of ACL permissions? &lt;/p&gt;
&lt;p&gt;I am try to decipher the ACL format of icacls, at it is simply so hard to find any readable and reliable information about this. Would you know where I might find some?&lt;/p&gt;
&lt;p&gt;I see from your technet webpage that you left the company. Congratulations. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=7427" width="1" height="1"&gt;</description></item><item><title>re: Mitigate the Image Uploader Vulnerabilities</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/02/06/mitigate-the-image-uploader-vulnerabilities.aspx#7425</link><pubDate>Sun, 10 Feb 2008 18:19:25 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:7425</guid><dc:creator>jesper</dc:creator><description>&lt;p&gt;Of course Aaron. I meant to say startup script. Fixing now.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=7425" width="1" height="1"&gt;</description></item><item><title>re: Mitigate the Image Uploader Vulnerabilities</title><link>http://msinfluentials.com/blogs/jesper/archive/2008/02/06/mitigate-the-image-uploader-vulnerabilities.aspx#7424</link><pubDate>Sun, 10 Feb 2008 14:15:04 GMT</pubDate><guid isPermaLink="false">91db4bc3-5a69-4a9f-94bf-eedb569902ab:7424</guid><dc:creator>Aaron Margosis</dc:creator><description>&lt;p&gt;I think it&amp;#39;s more accurate to call it a &amp;quot;startup script&amp;quot; rather than a &amp;quot;logon script&amp;quot;: &amp;nbsp;logon scripts run in the security context of the user logging on, while startup scripts run as System. &amp;nbsp;You need the latter here, since users can&amp;#39;t set those kill bits. &amp;nbsp;(The instructions you wrote indicate a &amp;quot;startup script&amp;quot;, which is correct, so it&amp;#39;s just about terminology.)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msinfluentials.com/aggbug.aspx?PostID=7424" width="1" height="1"&gt;</description></item></channel></rss>