Jump to content

Leaderboard

Popular Content

Showing content with the highest reputation on 07/17/15 in all areas

  1. Windows 10 RTM (10240) Close/Preview apps without autentification Windows 10 is a personal computer operating system being developed by Microsoft as part of the Windows NT family of operating systems. A new update to this OS is the three finger swipe up gesture, that opens the multiple screen mode and shows all the active apps, to allow them to be sorted/opened/closed/minimized. This feature also works without the user being logged in, potentially allowing an attackers to examine the running programs or close them. By allowing an attacker to maximize random apps could lead to running unwanted code on locked machines. Preliminary tests show that on maximize events do trigger on maximize events (WM_SIZE message with the value SIZE_MAXIMIZED in wParam). This may allow an attacker to activate a previously installed backdoor on a user machine, and run it only on maximize if the screen is locked (thus, allowing him to run arbitrary code without logging in if he has physical access to the machine). POC of this exploit: In the first picture we can observe a Wordpad Document opened and a Google Chrome minimized Lock the screen. Note: I have a password that is required for unlocking Screen is locked Execute the 3 fingers swipe up gesture with the touchpad I can see all the running apps with a GUI that are minimized. Moreover, I can see a preview of them, maximize them, or close them. Note that I can see the text "Sensitive information without logging in" I clicked chrome. After that I clicked space to open the login screen. I am logging in with my password Chrome is maximized. I've managed to preview an app (see sensitive text) and maximize another app without entering my login password. Source: em @ Romanian Security Team.
    1 point
  2. Ce ai scris tu ar trebui sa fie o intrebare la signup pe forum. also, mi-ai amintit de o treaba: Cand un soft foloseste ca licenta HWID, se calculeaza in functie de un set de componente standard (gen cpu+mb invariabil) sau pot sa-l fac cum vreau eu?
    1 point
  3. Nici o problema. Daca nu lasa doar in registrii, schimbi calculatorul
    1 point
  4. Versiunea trial la ce? Ma indoiesc ca un program serios isi lasa urme doar in registry
    1 point
  5. Changing your phone plan between different carriers is a mammoth task these days. All those requests, applications, and SIM card replacements are just too much. But, in near future, this could be a thing of past, and switching your carrier will be a lot easier. This may happen as Samsung and Apple are working to make the SIM card disappear. Source : Samsung and Apple are Working to Make SIM Card Disappear
    1 point
  6. Defapt este !==0 I-am contactat prin email si le-am spus de ce hosteaza un site care se ocupa cu spalare de bani? Au spus ca nu au auzit de PerfectMoney si m-au rugat sa le dau link-ul. Le-am dat link-ul, datele ip-urilor etc + informatii despre PM cum discuta lumea despre ei. @sleed mintea ta de Sysadmin de doi bani ramane limita in totalitate spre /dev/null.
    1 point
  7. Am un cont filelist: M-am gandit sa alegeti un numar de la 1 la 100 (aveti voie sa postati DOAR 1 singur numar, 1 singura data si DOAR pana maine la ora 20:00). Castigatorul va fi ales pe RANDOM
    -1 points
  8. Caut de ce vreme o clona ok dupa Airbnb insa singura pe care am gasit-o este: Airbnb Clone | Airbnb Clone Script | Rental Management Software Script | Marketplace Script | Cogzidel Shop Iar versiunea completa costa $2.000, total exagerat. Airbnb Clone | Airbnb Clone Script | Rental Management Software Script | Marketplace Script | Cogzidel Shop Poate a reusit cineva sa faca nulled din free versionul lor.. Thanks!
    -1 points
  9. Am o nelamurire... Am incercat sa gasesc pe forum dar nu prea am gasit... Cum se poate obtine V.I.P pe rst ? pe baza de donatii ? Chiar sunt curios sa stiu daca stie cineva....
    -1 points
This leaderboard is set to Bucharest/GMT+03:00
×
×
  • Create New...