F
Fernando
Hi all,
I was thinking about the possibility to fake the UAC prompt for
credentials by a malicious process, in order to get the admin password.
In example, a malicious process shows a fake UAC dialog prompting for
Admin credentials when started, and then stores the admin password for
later sending or wathever. Since Vista shows too many UAC dialogs, I
think we will enter the admin credentials in a mechanichal way, so this
exploit could be possible and easy to implement.
I'm missing some important technichal data about UAC which prevents
this? What do you think?
Fernando
I was thinking about the possibility to fake the UAC prompt for
credentials by a malicious process, in order to get the admin password.
In example, a malicious process shows a fake UAC dialog prompting for
Admin credentials when started, and then stores the admin password for
later sending or wathever. Since Vista shows too many UAC dialogs, I
think we will enter the admin credentials in a mechanichal way, so this
exploit could be possible and easy to implement.
I'm missing some important technichal data about UAC which prevents
this? What do you think?
Fernando