https://forums.symantec.com/syment/board/message?board.id=endpoint_protection11&message.id=26289
--------------------------------------------------
From: "Sandeep Cheema" <51l3n7@live.in>
Sent: Friday, February 20, 2009 11:01 AM
To: <bugtraq@securityfocus.com>
Subject: Re: SEPKILL /im SMC.EXE /f
> Privilege Escalation attack
--------------------------------------------------
From: "Sandeep Cheema" <51l3n7@live.in>
Sent: Thursday, February 19, 2009 12:50 PM
To: <bugtraq@securityfocus.com>
Subject: Re: SEPKILL /im SMC.EXE /f
> Please note the following. I have reported this to Symantec at
Regards, Sandeep
--------------------------------------------------
From: "David Calabro" <dcalabro@transitionalwork.org>
Sent: Saturday, February 14, 2009 1:02 AM
To: "'Sandeep Cheema'" <51l3n7@live.in>; <bugtraq@securityfocus.com>
Subject: RE: SEPKILL /im SMC.EXE /f
> If the Symantec Management Client service was somehow changed from
> "smc.exe" to "smc.exe -P" it would effectively prevent the service from
> starting in the first place. Correct?
If the Symantec Management Client service was somehow changed from "smc.exe" to "smc.exe -P" it would effectively prevent the service from starting in the first place. Correct?
-----Original Message-----
From: Sandeep Cheema [mailto:51l3n7@live.in]
Sent: Friday, February 13, 2009 12:25 PM
To: bugtraq@securityfocus.com
Subject: Re: SEPKILL /im SMC.EXE /f
Just as an update couldn't get any further other than t.he fact that
SMCGui.exe is getting killed as its running in the user account and SMC.exe
Thank you.
Regards, Sandeep
--------------------------------------------------
From: "Sandeep Cheema" <51l3n7@live.in>
Sent: Friday, February 13, 2009 8:06 PM
To: <bugtraq@securityfocus.com>
Subject: Re: SEPKILL /im SMC.EXE /f
> For the "users" its working for SmcGUI.exe
.--------------------------------------------------
From: "Jon Kloske" <jon@uq.edu.au>
Sent: Friday, February 13, 2009 9:11 AM
To: "Sandeep Cheema" <51l3n7@live.in>
Cc: <bugtraq@securityfocus.com>
Subject: RE: SEP(Symantec) Bug
> Hi Sandeep,
>
Thank you.
Regards, Sandeep
--------------------------------------------------
From: "Sandeep Cheema" <51l3n7@live.in>
Sent: Friday, February 13, 2009 7:03 PM
To: <bugtraq@securityfocus.com>
Subject: Re: SEPKILL /im SMC.EXE /f
> As an update its not happening for "Users" account, Though no access
jon@uq.edu.au :: x54193 :: 78-516B
Faculty of EAIT, UQ :: CRICOS No. 00025B
> -----Original Message-----
> From: Sandeep Cheema [mailto:51l3n7@live.in]
> Sent: Friday, 13 February 2009 12:16 AM
> To: bugtraq@securityfocus.com
> Subject: SEP(Symantec) Bug
>
> Hi,
Thank you.
Regards, Sandeep
--------------------------------------------------
From: "Sandeep Cheema" <51l3n7@live.in>
Sent: Friday, February 13, 2009 6:18 PM
To: <bugtraq@securityfocus.com>
Subject: SEPKILL /im SMC.EXE /f
> Hi,