[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] LSADump2 Crashing Windows
- To: full-disclosure@xxxxxxxxxxxxxxxxx
- Subject: [Full-disclosure] LSADump2 Crashing Windows
- From: oh face <0h.fac3@xxxxxxxxx>
- Date: Fri, 2 Sep 2005 14:41:39 -0400
In my recent experience, LSADump2 has been crashing Windows boxes. I was
able to verify this on fully patched Windows XP and 2003. In further
examination, LSADump2, when executed, killed the "lsass" process, and with
the "winlogon" process still running, the system was forced to reboot. As
far as I know, LSADump2 is utilizing a DLL injection technique to dump the
contents of LSA secrets.
Question:
1. Has anyone had this experience? If so, is there a safe method to execute
this tool?
2. When I tested LSADump2 on various Windows boxes, not all fully patched
boxes were affected by this issue. What configuration of Windows is exactly
causing "lsass" to fail?
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/