Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

RandomEntropy

@R41N3RZUF477@infosec.exchange
  • Open on infosec.exchange

Just another random IT security researcher.

0 Followers
0 Following
4 Posts
Joined November 21, 2025
GitHub:
https://github.com/R41N3RZUF477

Posts

Open post
R41N3RZUF477
RandomEntropy @R41N3RZUF477@infosec.exchange · 5d ago
RandomEntropy
@R41N3RZUF477@infosec.exchange

Just another random IT security researcher.

infosec.exchange
Replying to @tiraniddo@infosec.exchange
@tiraniddo@infosec.exchange Privilege is only necessary if user is not admin 🙂 . Other question: Is there any COM lib, where loading and creating an instance (using COM lib as proxy) result in process pwnage?
0
0
0
0
Open post
R41N3RZUF477
RandomEntropy @R41N3RZUF477@infosec.exchange · 5d ago
RandomEntropy
@R41N3RZUF477@infosec.exchange

Just another random IT security researcher.

infosec.exchange
Replying to @tiraniddo@infosec.exchange
@tiraniddo@infosec.exchange PPL, but not PP suggests either because of Windows System DLLs that are not signed by file, but by catalog or because of a target program is signed for up to PPL-WinTCB. Now it needs to be hilariously trivial ... Maybe an oversight in loading catalog signed files? I haven't tried Windows redirection DLLs, but I'm sure they wouldn't load unless the DLL can be mapped from an outside process first. Maybe it has to do with loading an (old) vulnerable Windows System DLL that has no file signing? Maybe a COM DLL? Could it be a COM DLL loaded into WerFaultSecure.exe? At least I remember I have seen, that this program can load a COM DLL under certain circumstances. That would explain the wording. Sadly I'm not an expert in COM, so I don't know if there is an obvious "hey load this COM and you're pwned". 🤔 Hopefully I don't produce a duplicate. You jump scared me with PPL-WinTCB. I work on PPL bypass that can be run as system or as user, but as user only with SeBatchLogonRight. Hope that's not a duplicate.
0
1
0
0
Open post
R41N3RZUF477
RandomEntropy @R41N3RZUF477@infosec.exchange · Mar 01, 2026
RandomEntropy
@R41N3RZUF477@infosec.exchange

Just another random IT security researcher.

infosec.exchange
Replying to @tiraniddo@infosec.exchange
@tiraniddo Finally, the post I waited for. Back in 2023 I searched for a UAC bypass that is compatible with "always notify" and Windows 10 upwards to complete my chain for any Windows UAC bypass. I used your token reading UAC bypass as a base for older Windows systems. Then I just found CVE-2023-41772 by accident. So this route was burned or at least I thought it was. Then I tried to find a UIAccess bypass and it worked again. That was the moment where I knew not auto-elevate but UIAccess is (and will be) the biggest weakness of UAC. Even without GetProcessHandleFromHwnd there are more options like CSRSS activation cache poisoning, COM injection, abusing WER, ... As far as I have seen the newest version of administrator protection still has at least one bug, that let's you bypass it, but after the chaos of the first "release", I will rather wait for the full release. Anyway the PPL bypass might be fixed, but I have another PPL bypass that is "fixed" in 24H2 but still works on 25H2 and preview. The bug is simple, but (unique) exploitation is so dumb, I don't know what to say ... 😅
1
1
0
0
Open post
R41N3RZUF477
RandomEntropy @R41N3RZUF477@infosec.exchange · Jan 19, 2026
RandomEntropy
@R41N3RZUF477@infosec.exchange

Just another random IT security researcher.

infosec.exchange

I guess handle spraying is a thing now ...

0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 09:24:58 UTC