DEMO: attackers can bypass AppLocker to execute arbitrary programs.

Source: Internet
Author: User

Recently, a new feature named AppLocker in Windows 7 is popular among anti-virus enthusiasts.

If you are a security expert, you will know what the program is allowed to do. It is very dangerous. You will also know what functions the program should have and what functions it should not have. What you want to get is a set, never-disturbing solution. Applocker is quite practical for security experts.

Figure 2

Applocker settings window

Don't know what AppLocker is, please see: http://edge.technet.com/Media/Windows-7--AppLocker-Chinese)

I checked a lot of information and found that this function can be bypassed, but it is much more reliable than the original group policy.

Traditional Group Policy software restricts SRP.) The parent process is verified by CreateProcess-> CreateProcessInternalW-> BasepCheckWinSaferRestrictions.

AppLockerSLPv2 in Windows 7) is jointly controlled by a driver discache and a system service AppIDSvc.

This program can bypass the AppLocker Software Restriction Policy SRPv2 on Windows 7 Ultimate Operating System under the Administrator account without elevation of permissions to execute any program,
Theoretically, it can also bypass the traditional group policy to limit SRP) to execute arbitrary programs.

Go to SkyDrive: http://cid-ad319598642e8326.skydrive.live.com/self.aspx/Public/Others/BypassRestrictions.zip to download the DEMO program

Or Kaka Forum: http://bbs.ikaka.com/showtopic-8687866.aspx

The source code will not be sent. Everyone knows the shortcut keys for viewing the source code.

See: http://technet.microsoft.com/en-us/library/ee844115 (WS.10). aspx

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.