Author Topic: Startup Repair?  (Read 1202 times)

0 Members and 1 Guest are viewing this topic.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Startup Repair?
« on: December 05, 2014, 01:03:58 AM »
Hey Hey!

So, as always, my head is on the line at school. Apparently they expect me to fix this exploit. Not very impressed, but I'll pass it on to the technicians later on!

Essentially, what's been found is using the Startup Repair, integrated into Windows (Fails boot once normal, then a second attempt in Safe Mode, if both fail, you get the option.) is that, after it's done, the little window pops up with 2 "links" at the bottom. The last one, directs you to a notepad document which you can then "Save As". Since no restrictions can be set in this mode, it's easily abusable for renaming/Deleting/moving/Accessing files (Which is the issue).

Now, the issue is. I don't know how to stop that option from coming up. Upon some googling (My best friend, and worst nightmare) it showed the following command.

bcdedit /set {default} recoveryenabled No

Any truth to it? My VM's don't want to work, and setting one up is a pain the the ***.



VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.