WINDOWS PRIVILEGE ESCALATION THROUGH NETWORK BACKDOOR AND INFORMATION MINING USING USB HACKTOOL

Authors

  • Hidayat Ul Hazazi Bin Ab Wahab Faculty of Computer and Mathematical Sciences, UiTM Shah Alam, Selangor, Malaysia
  • Jasni Mohamad Zain Faculty of Computer and Mathematical Sciences, UiTM Shah Alam, Selangor, Malaysia

DOI:

https://doi.org/10.24191/mjoc.v3i1.4811

Keywords:

Attack, Universal Serial Bus, Hacking, Data Mining, Backdoor, Metasploit

Abstract

A privilege escalation in the Windows system can be defined as a method of gaining access to the kernel system and allowing the user to have an administrative access to the local admin account system on the computer. This paper describes the proof of concept attack scheme using Universal Serial Bus (USB) Hacktool. The attack scheme, the same interaction on the physical access to the computer system could be accomplished by the attacker using a little effort on social engineering and specialized USB Hacktool to take over the computer system in full where it will collect valuable information and escalate the administrative privilege to gain unauthorized admin access which further attack can be done like setting up an open port for backdoor access. The evaluation of this paper gives a significant value as for educational purpose for proof of concept security project. The implementation on this project could help the responsible team to take necessary action toward physical security access to their computer or workstation.

References

Badshah G, Liew S. C., Jasni Mohamad Zain, Mushtaq Ali (2016), Watermark Compression in Medical Image Watermarking Using Lempel-Ziv-Welch (LZW) Lossless Compression Technique. Journal of Digital Imaging 29(2), pages 216-255.

Bang, J., et al. (2010). "Secure USB bypassing tool." Digital Investigation 7, Supplement(0): S114-S120.

Boukhobza, J. and C. Timsit (2005). On windows file access modes: a performance study. Proceedings of the 4th international symposium on Information and communication technologies. Cape Town, South Africa, Trinity College Dublin: 44-49.

Carvey, H. and C. Altheide (2005). "Tracking USB storage: Analysis of windows artifacts generated by USB storage devices." Digital Investigation 2(2): 94-100.

Carvey, H. (2005). "The Windows Registry as a forensic resource." Digital Investigation 2(3): 201-205.

Ciprian Adrian Rusen (2017, November 7). What is UAC (User Account Control) and why you should never turn it off. Retrieved from https://www.digitalcitizen.life/uac-why-you-should-never-turn-it-off

Gorge, M. (2005). "USB & other portable storage device usage: Be aware of the risks to your corporate data in order to take pre-emptive and/or corrective action." Computer Fraud & Security 2005(8): 15-17.

Lee, C. C. K. (2013). USB Hardware Trojan Horse Device Attack. Ann Arbor, University of California, Irvine. 1539896: 59.

Microsoft Technet (2012, August 31). How User Account Control Works. Retrieved from https://technet.microsoft.com/en-us/library/jj574202(v=ws.11).aspx

NetbiosX (2017, May 2). UAC Bypass – Event Viewer. Retrieved from https://pentestlab.blog/2017/05/02/uac-bypass-event-viewer/

Trend Micro (2015, January 7). Backdoor attacks: How they work and how to protect against them. Retrieved from http://blog.trendmicro.com/backdoor-attacks-work-protect/

Zain, J M and Malcolm Clarke (2005), “LSB Reversible Watermarking Surviving JPEG Compression”, in The 27th Annual International Conference of the IEEE Engineering in Medicine and Biology Society, Shanghai, China, 1-4 September 2005.

Zhu, J., Chu, B., & Lipford, H. (2016). Detecting Privilege Escalation Attacks through Instrumenting Web Application Source Code. Paper presented at the Proceedings of the 21st ACM on Symposium on Access Control Models and Technologies, Shanghai, China.

Published

2018-06-01

How to Cite

Hidayat Ul Hazazi Bin Ab Wahab, & Jasni Mohamad Zain. (2018). WINDOWS PRIVILEGE ESCALATION THROUGH NETWORK BACKDOOR AND INFORMATION MINING USING USB HACKTOOL. Malaysian Journal of Computing, 3(1). https://doi.org/10.24191/mjoc.v3i1.4811