4 ms·
Neat, but replacing Utilman.exe with cmd.exe using most Linux ISOs is easy, and I've already got the drives needed. The amount of customers that get locked out
by catboybotnet 3y ago
Neat, but replacing Utilman.exe with cmd.exe using most Linux ISOs is easy, and I've already got the drives needed. The amount of customers that get locked out of their servers...
- shawnz 3y agoThey actually recently made this attack vector more difficult with a recent Windows Defender update: https://security.stackexchange.com/a/176456 https://security.stackexchange.com/a/176456
- jesprenj 3y agoA trick I used that still worked after this Defender update (tested some months ago) is replacing Magnify.exe with ftp.exe. This does not make Defender suspicipus, but one can open Magnify.exe from the lock screen and one can execute commands from within the ftp.exe shell by prefixing them with !. This is great, because ftp.exe binary is signed by Microsoft and is a completely legit binary (: