Bugtraq mailing list archives
Re: Get admin rights using Doro (pdf creator)
From: <the_sz () gmx co uk>
Date: 19 Jan 2004 14:43:27 -0000
In-Reply-To: <7814219078.20031214220641 () portsonline net> I'm the author of Doro. Version 1.15 fixes this problem. run.to/sz
Received: (qmail 2135 invoked from network); 15 Dec 2003 20:22:15 -0000 Received: from outgoing2.securityfocus.com (205.206.231.26) by mail.securityfocus.com with SMTP; 15 Dec 2003 20:22:15 -0000 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing2.securityfocus.com (Postfix) with QMQP id 0FDF48FCEE; Mon, 15 Dec 2003 07:27:49 -0700 (MST) Mailing-List: contact bugtraq-help () securityfocus com; run by ezmlm Precedence: bulk List-Id: <bugtraq.list-id.securityfocus.com> List-Post: <mailto:bugtraq () securityfocus com> List-Help: <mailto:bugtraq-help () securityfocus com> List-Unsubscribe: <mailto:bugtraq-unsubscribe () securityfocus com> List-Subscribe: <mailto:bugtraq-subscribe () securityfocus com> Delivered-To: mailing list bugtraq () securityfocus com Delivered-To: moderator for bugtraq () securityfocus com Received: (qmail 13164 invoked from network); 14 Dec 2003 21:02:05 -0000 Date: Sun, 14 Dec 2003 22:06:41 +0100 From: Ramon Kukla <ml () portsonline net> X-Mailer: The Bat! (v2.01.3) Personal Reply-To: Ramon Kukla <ml () portsonline net> X-Priority: 3 (Normal) Message-ID: <7814219078.20031214220641 () portsonline net> To: bugtraq () securityfocus com Subject: Get admin rights using Doro (pdf creator) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Hi, a few days ago i discovered a bug in Doro[1]. Doro is a free tool to create pdf files from any windows program. After installing Doro you have a new printer called 'Doro PDF Writer'. If you select 'Print' the spooler calls the printer filter 'doro.dll'. The 'doro.dll' then starts 'doro.exe' and a file requester appears. I guess that most of you see the problem. The spooler is controlled by the account 'system'. Therefore the file requester has the same rights. It's easy now to create a new user and move them into the group 'admins'. I informed the coder of the software and he approved the problem. regards Ramon [1] http://www.geocities.com/the_real_sz/misc/doro.htm
Current thread:
- Re: Get admin rights using Doro (pdf creator) the_sz (Jan 19)