Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86379506

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

#Exploit Title: Winstep 18.06.0096 - 'Xtreme Service' Unquoted Service Path
#Exploit Author : SamAlucard
#Exploit Date: 2020-11-08
#Vendor : Winstep
#Version : WsxService 18.06.0096
#Vendor Homepage :  https://www.winstep.net/xtreme.asp
#Tested on OS: Windows 7 Pro

#Analyze PoC :
==============

C:\>sc qc "Winstep Xtreme Service"
[SC] QueryServiceConfig CORRECTO

NOMBRE_SERVICIO: Winstep Xtreme Service
        TIPO               : 10  WIN32_OWN_PROCESS
        TIPO_INICIO        : 2   AUTO_START
        CONTROL_ERROR      : 1   NORMAL
        NOMBRE_RUTA_BINARIO: C:\Program Files\Winstep\WsxService
        GRUPO_ORDEN_CARGA  :
        ETIQUETA           : 0
        NOMBRE_MOSTRAR     : Winstep Xtreme Service
        DEPENDENCIAS       :
        NOMBRE_INICIO_SERVICIO: LocalSystem