Re: Operational? or Test Software?
If test s/w is running on XP I don't see what the fuss is about.
Windows 10 is Swiss Cheese
Windows 8.1 is Swiss Cheese
Windows 8 is Swiss Cheese
Windows 7 is Swiss Cheese
Windows Vista is Swiss Cheese
Windows XP is Swiss Cheese
Windows 2k is Swiss Cheese
Windows NT4 is Swiss Cheese
Windows 2016 (all versions) is Swiss Cheese
Windows 2012 R2 (all versions) is Swiss Cheese
Windows 2008 R2 is Swiss Cheese
Windows 2008 is Swiss Cheese
Windows 2003 is Swiss Cheese
Anythings after, between, and before is Swiss Cheese.
Get the picture or need some more ? I could have written Windows is Swiss Cheese, but then you would have stupidly asked "Which version, Windows 95 ?" ....
As I have already written multiple times, I can easily impersonate anybody who is currently logged on to any of those systems, enterprise-wide, with local admin rights ... which I can easily gain with a malformed PDF, Word, Font, flash file ... you name it ... any system a currently logged on user has access to, I can log on to, gain local admin rights and spread ... it is dead easy. This problem is due to the fact MS think because they have proprietary software, hidden API's, they think that user x who has local admin rights on system y has these rights limited to system y, which is not the case, again, I only use standard API's ... If I can convince a domain admin to log on to my system, to troubleshoot an issue I would have created, I own the domain ... any computer in the domain, that has a session open as a user from another domain admin (from another domain) in the forest, I can become domain admin in that domain ... and so forth, here, no exploit needed ... Now, try that on a Linux box in a domain .... won't happen ... ;-)
A zero day, or a gullible domain admin and I own your enterprise. Thing is, MS do not know how I do it, it is dead simple, scriptable, no "exploit needed for the spread" ... I use published API's ... they are dumb enough to publish them ... and have not yet figured out how I do it ... been doing it since Windows 2003 ... and it works from 2k onwards ..., never tested NT4 ... it still works in 2016, i tested it ... ;-)