3 ms·
I had always assumed that one application could not touch the memory of another application. Does running as Admin allow breaking this boundary?
by jbritton 4y ago
I had always assumed that one application could not touch the memory of another application. Does running as Admin allow breaking this boundary?
- codedokode 4y agoThis is wrong, on Windows there are system calls to access memory of other process and on Linux you can do it using debugging. Also on Windows there is a tradition to inject libraries into other processes, create threads in processes etc.
- account42 4y agoOn Linux, ptrace permissions can be restricted [0] and some distributions do this by default. Whether this provides any meaningful security is questionable unless you pair it with filesystem isolation to prevent malicious programs from modifying config files / bashrc / etc. Meanwhile it does make legit uses of ptrace more annoying. [0] https://www.kernel.org/doc/Documentation/security/Yama.txt https://www.kernel.org/doc/Documentation/security/Yama.txt
- rootw0rm 4y agoYes. However, I think parent process can gain access to child process memory without admin rights.
- insanitybit 4y agoAll that's generally required is being the same user at the same or higher integrity.
- genocidicbunny 4y agoYes, in general on Windows processes with higher privilege levels can get access to read/write another processes memory, or even inject code into them. And even Admin-level processes can still be broken into by something running as a service with even more elevated privileges like NT AUTHORITY\SYSTEM. This has long been a leaky part of Windows security. If your malware can get its code running inside a highly privileged service or process, it can do more or less whatever it wants to the rest of the system. But even when not used for nefarious purposes, it is still an extremely dangerous capability in that it can be very easy to create problems .
- Hikikomori 4y agoAnything you run as your user can be accessed.
- genewitch 4y agocheatengine, wemod, and so on would not be able to work if this were the case. Thankfully those all work, at least up to windows 10!
- genocidicbunny 4y agoOr userland debuggers.
- jquery 4y agoThey work just fine in windows 11 so far.
- jchw 4y agoBy default, any application's memory can be read and written to by other processes running as the same user, as far as I know. The way to deal with this is to set process security descriptors, but admin can still bypass this. There are protected processes, and protected processes light, but those are not used by most software (mainly anti-malware afaik.) https://learn.microsoft.com/en-us/windows/win32/procthread/process-security-and-access-rights https://learn.microsoft.com/en-us/windows/win32/procthread/p...
- userbinator 4y agoThere are protected processes, and protected processes light, but those are not used by most software (mainly anti-malware afaik.) ...and DRM.
- swagmoney1606 4y agoThis is an EXTREMELY common pattern in the world of Windows... Especially with antivirus
- Iwan-Zotow 4y agoHow you debug then?