[Full-disclosure] Outpost Firewall vulnerability, users gaining system rights

H. Wiedemann dpr at herr-der-mails.de
Sat Jul 22 19:05:05 BST 2006


And an even more simple method in version 3.51.759.xxxx:

"Options - Application - Components - Edit List - Add"

This dialog doesn't have a disabled context menu, so just go to the 
windows\system32 folder, right click on "cmd.exe" and choose "open".

More vulnerabilites to come unless Agnitum separates the service and the 
GUI parts ;)

-- 

H. WIEDEMANN




Full-Disclosure is hosted and sponsored by Secunia.