<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: My second playdate with utilman.exe</title>
	<atom:link href="http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/</link>
	<description>(blog 'DidierStevens)</description>
	<lastBuildDate>Tue, 09 Mar 2010 09:33:38 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-35876</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Tue, 06 Oct 2009 19:06:59 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-35876</guid>
		<description>Yes, \\ The \\\\ stems from an old issue with the PRE format in Wordpress.</description>
		<content:encoded><![CDATA[<p>Yes, \\ The \\\\ stems from an old issue with the PRE format in WordPress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: MF</title>
		<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-35870</link>
		<dc:creator>MF</dc:creator>
		<pubDate>Tue, 06 Oct 2009 07:03:04 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-35870</guid>
		<description>The example only works for me when
  LPTSTR szDesktop = _tcsdup(TEXT(&quot;WinSta0\\\\Winlogon&quot;));
is replaced with
  LPTSTR szDesktop = _tcsdup(TEXT(&quot;WinSta0\\Winlogon&quot;));

The \ has to be doubled (not quadrupled) for masking.</description>
		<content:encoded><![CDATA[<p>The example only works for me when<br />
  LPTSTR szDesktop = _tcsdup(TEXT(&#8220;WinSta0\\\\Winlogon&#8221;));<br />
is replaced with<br />
  LPTSTR szDesktop = _tcsdup(TEXT(&#8220;WinSta0\\Winlogon&#8221;));</p>
<p>The \ has to be doubled (not quadrupled) for masking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacky</title>
		<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-30710</link>
		<dc:creator>Jacky</dc:creator>
		<pubDate>Wed, 16 Apr 2008 13:56:51 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-30710</guid>
		<description>Hi, i compile you&#039;re script with no error, replace in dllcache and system32, block sfc when prompt to restore, but when i press &quot;Windows key&quot; + U, nothing, you&#039;re script in the 3 exemple work, but not the last with CMD.</description>
		<content:encoded><![CDATA[<p>Hi, i compile you&#8217;re script with no error, replace in dllcache and system32, block sfc when prompt to restore, but when i press &#8220;Windows key&#8221; + U, nothing, you&#8217;re script in the 3 exemple work, but not the last with CMD.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Playing with utilman.exe, The Motion Picture &#171; Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-89</link>
		<dc:creator>Playing with utilman.exe, The Motion Picture &#171; Didier Stevens</dc:creator>
		<pubDate>Tue, 05 Sep 2006 10:00:26 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-89</guid>
		<description>[...] For a demo of My second playdate with utilman.exe, go here on YouTube. [...]</description>
		<content:encoded><![CDATA[<p>[...] For a demo of My second playdate with utilman.exe, go here on YouTube. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: evilbitz</title>
		<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-78</link>
		<dc:creator>evilbitz</dc:creator>
		<pubDate>Fri, 01 Sep 2006 20:00:56 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-78</guid>
		<description>It doesn&#039;t matter on which desktop the cmd runs.
utilman.exe always runs as SYSTEM.

Nice man ;-)</description>
		<content:encoded><![CDATA[<p>It doesn&#8217;t matter on which desktop the cmd runs.<br />
utilman.exe always runs as SYSTEM.</p>
<p>Nice man <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Didier Stevens</title>
		<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-76</link>
		<dc:creator>Didier Stevens</dc:creator>
		<pubDate>Fri, 01 Sep 2006 16:28:54 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-76</guid>
		<description>It&#039;s the SYSTEM account, read this: http://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/</description>
		<content:encoded><![CDATA[<p>It&#8217;s the SYSTEM account, read this: <a href="http://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/" rel="nofollow">http://didierstevens.wordpress.com/2006/08/21/playing-with-utilmanexe/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jay</title>
		<link>http://blog.didierstevens.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-73</link>
		<dc:creator>Jay</dc:creator>
		<pubDate>Fri, 01 Sep 2006 14:14:32 +0000</pubDate>
		<guid isPermaLink="false">https://didierstevens.wordpress.com/2006/08/31/my-second-playdate-with-utilmanexe/#comment-73</guid>
		<description>What user account does the shell run as?  If it is system then their is a huge security hole.</description>
		<content:encoded><![CDATA[<p>What user account does the shell run as?  If it is system then their is a huge security hole.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
