Skip to content

Comment on Security researchers 'destroy' Microsoft ASP.NET securityparent

Comments

What do you mean by "local SYSTEM"?

I eagerly look forward to details on it. Where might I find them?

> What do you mean by "local SYSTEM"?

The highest system privilege level on Windows. They were able to interactively run CMD.EXE as the LocalSystem account on the remote web server.

> I eagerly look forward to details on it. Where might I find them?

The details were not disclosed until today when the attack was presented at a security conference. As far as I know there isn't anything available online yet, but that should change very soon.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.