<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Playing with utilman.exe</title>
	<atom:link href="http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Tue, 16 Mar 2010 07:37:33 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-35875</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Tue, 06 Oct 2009 19:06:00 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-35875</guid>
		<description>And you&#039;ve done the necessary to prevent Windows File Protection from restoring the original utilman.exe?

You can try what&#039;s explained in comment #16 as an alternative to circumventing WFP.</description>
		<content:encoded><![CDATA[<p>And you&#8217;ve done the necessary to prevent Windows File Protection from restoring the original utilman.exe?</p>
<p>You can try what&#8217;s explained in comment #16 as an alternative to circumventing WFP.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MF</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-35869</link>
		<dc:creator>MF</dc:creator>
		<pubDate>Tue, 06 Oct 2009 06:13:33 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-35869</guid>
		<description>Yes, I compiled the third example and replaced the &quot;Default&quot;-Desktop with &quot;Winlogon&quot;.

Still not working...</description>
		<content:encoded><![CDATA[<p>Yes, I compiled the third example and replaced the &#8220;Default&#8221;-Desktop with &#8220;Winlogon&#8221;.</p>
<p>Still not working&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-35865</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Mon, 05 Oct 2009 16:28:59 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-35865</guid>
		<description>It only works if you compile the program and replace utilman.exe with it.</description>
		<content:encoded><![CDATA[<p>It only works if you compile the program and replace utilman.exe with it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MF</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-35864</link>
		<dc:creator>MF</dc:creator>
		<pubDate>Mon, 05 Oct 2009 10:41:17 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-35864</guid>
		<description>Hi all, does somebody know if MS changed the described functionality?

I cannot start a visible process on Windows XP SP3 with Win + U. Only the real utilman.exe is doing this.
If I start it normally in a user session, the message is shown just fine.

Thx, best regards</description>
		<content:encoded><![CDATA[<p>Hi all, does somebody know if MS changed the described functionality?</p>
<p>I cannot start a visible process on Windows XP SP3 with Win + U. Only the real utilman.exe is doing this.<br />
If I start it normally in a user session, the message is shown just fine.</p>
<p>Thx, best regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-33043</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 04 Jul 2008 17:51:08 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-33043</guid>
		<description>I&#039;ve made a movie for XP about 2 years ago: http://blog.didierstevens.com/2006/09/05/playing-with-utilmanexe-the-motion-picture/

If you replace utilman.exe on XP, you&#039;ll see WFP in action as it replaces utilman.exewith the cached original file. This is a feature thathas been abandoned in Vista.

I wonder if my video inspired Offensive Security.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve made a movie for XP about 2 years ago: <a href="http://blog.didierstevens.com/2006/09/05/playing-with-utilmanexe-the-motion-picture/" rel="nofollow">http://blog.didierstevens.com/2006/09/05/playing-with-utilmanexe-the-motion-picture/</a></p>
<p>If you replace utilman.exe on XP, you&#8217;ll see WFP in action as it replaces utilman.exewith the cached original file. This is a feature thathas been abandoned in Vista.</p>
<p>I wonder if my video inspired Offensive Security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ZenMasterBob</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-33040</link>
		<dc:creator>ZenMasterBob</dc:creator>
		<pubDate>Thu, 03 Jul 2008 18:15:13 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-33040</guid>
		<description>Over at Offensive Security they have a video instruction where they simply renamed utilman.exe to utilman.old, then copied cmd.exe to utilman.exe, on a Vista machine.  It gives you a command prompt right from the login screen.

http://www.offensive-security.com/movies/vistahack/vistahack.html</description>
		<content:encoded><![CDATA[<p>Over at Offensive Security they have a video instruction where they simply renamed utilman.exe to utilman.old, then copied cmd.exe to utilman.exe, on a Vista machine.  It gives you a command prompt right from the login screen.</p>
<p><a href="http://www.offensive-security.com/movies/vistahack/vistahack.html" rel="nofollow">http://www.offensive-security.com/movies/vistahack/vistahack.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-30438</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Mon, 14 Apr 2008 11:59:29 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-30438</guid>
		<description>Thanks for the clarification.  I know that the Windows key and Sticky Keys function can be disabled.  Does anyone know of any other similar backdoors for XP?  I heard of the magnify.exe backdoor for Vista.</description>
		<content:encoded><![CDATA[<p>Thanks for the clarification.  I know that the Windows key and Sticky Keys function can be disabled.  Does anyone know of any other similar backdoors for XP?  I heard of the magnify.exe backdoor for Vista.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-30436</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Mon, 14 Apr 2008 10:22:53 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-30436</guid>
		<description>To avoid any confusion: this trick with utilman is not a local privilege escalation, it&#039;s a local backdoor.</description>
		<content:encoded><![CDATA[<p>To avoid any confusion: this trick with utilman is not a local privilege escalation, it&#8217;s a local backdoor.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-30320</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Sat, 12 Apr 2008 15:58:45 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-30320</guid>
		<description>I came across a similar &quot;trick&quot; using sethc.exe but I guess that Sticky Keys can be disabled.  I understand that this sort of behaviour can be seen with any file running as System but I guess that some such files might not take kindly to being messed around in this way!

Does anyone else have any tips about local privilege escalation (without prior knowledge of Admin PW) or files that run as System which can be used (safely)?</description>
		<content:encoded><![CDATA[<p>I came across a similar &#8220;trick&#8221; using sethc.exe but I guess that Sticky Keys can be disabled.  I understand that this sort of behaviour can be seen with any file running as System but I guess that some such files might not take kindly to being messed around in this way!</p>
<p>Does anyone else have any tips about local privilege escalation (without prior knowledge of Admin PW) or files that run as System which can be used (safely)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/21/playing-with-utilmanexe/#comment-25538</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 04 Jan 2008 20:27:36 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/#comment-25538</guid>
		<description>This is a clear indication that Windows detects a change in the sfcfiles.dll file. If you want, you can mail me the file and I&#039;ll have a look at it.</description>
		<content:encoded><![CDATA[<p>This is a clear indication that Windows detects a change in the sfcfiles.dll file. If you want, you can mail me the file and I&#8217;ll have a look at it.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
