Felix aka [xi-tauw]
77 posts
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
Felix aka [xi-tauw]
@PsiDragon
Windows Privilege Escalator
in da web Katılım Aralık 2010
28 Takip Edilen985 Takipçiler
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
@hFireF0X UACME method 20. Probably wasn't fixed properly.
English

@PsiDragon @hFireF0X hmm, but, how can we copy the dll file to C:\Windows\System32\wbem\ without having administrator privileged ?
English
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
GOG Galaxy. I almost forgot about this research by now (it was year ago), but the recent news about Cyberpunk 2077 reminded me that I haven’t publicly shared my research.
Rus - habr.com/ru/company/pm/…
Eng - amonitoring.ru/article/gog/
English
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
Little writeup for EOP for Dr.Web Security Space 12.
Rus - habr.com/ru/company/pm/…
Eng - amonitoring.ru/article/drweb/
English
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
Writeup for EOP for ABBYY FineReader (CVE-2019-20383).
Rus - habr.com/ru/company/pm/…
Eng - amonitoring.ru/article/abbyy-…
English
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
@taviso I converted this into UAC bypass some time ago. amonitoring.ru/article/uac_by…
English

Interesting question, is this a UAC bypass? My first thought is no, because UIPI means you can't automate the interaction. Therefore, the only way to exploit it is if you could have just clicked OK in the UAC consent anyway.... right? (yes, I know UAC is not a supported boundary)
Jihad abdrazak@harr0ey
[New-Post] UAC bypass using Perfmon.exe @mattharr0ey/uac-bypass-via-font-in-perfmon-exe-options-2b4779955d9e" target="_blank" rel="nofollow noopener">medium.com/@mattharr0ey/u…
English

![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)

@PsiDragon Nicely written post. For CVE-2019-19247, how were you sending commands to the named pipe? Is there a native command or script/tool to do interaction with a named pipe?
English
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
Writeup for EOP for Windows Origin client. (CVE-2019-19247 и CVE-2019-19248)
Rus - habr.com/ru/company/pm/…
Eng - amonitoring.ru/article/origin…
English
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
Writeup for third Steam vulnerability. #PublicDisclosure but not #0day this time, already patched.
Rus - habr.com/ru/company/pm/…
Eng - amonitoring.ru/article/steam_…
English
![Felix aka [xi-tauw]](https://pbs.twimg.com/profile_images/2570315036/c30p9ihncv66teu03rmc.jpeg)
store.steampowered.com/news/54236/
Third reported vulnerability has been fixed in main client. Hurray.
English

@PsiDragon so how to download old version steam for recurrencing the vulnerability?☹️
English



![Felix aka [xi-tauw] tweet media](https://pbs.twimg.com/media/ELmA2VcW4AAp2AC.png)

![Felix aka [xi-tauw] tweet media](https://pbs.twimg.com/media/EHdwACEWoAAj3lv.png)

