12.07.2015 Views

sR6uWE

sR6uWE

sR6uWE

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

INTERNALS: RESTRICTIONSRegistry KeysAccess MaskSandbox-SID (S-1-15-2-*-*-*-*-*-*-*)HKCR\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\HKCR \Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\\ChildrenHKCR \Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\\*HKCR \Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\HKCR \Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\\ChildrenHKCR \Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\\*HKEY_USERS\\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\HKEY_USERS\\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\\ChildrenHKEY_USERS\\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\\*KEY_READKEY_ALL_ACCESSKEY_ALL_ACCESSKEY_READKEY_ALL_ACCESSKEY_ALL_ACCESSKEY_READKEY_ALL_ACCESSKEY_ALL_ACCESSOffice-Capability-SID (S-1-15-3-2929230137-1657469040)HKCU\Software\Microsoft\Office\*HKEY_USERS\\Software\Microsoft\Office\*KEY_READKEY_READ• Sandbox-SID restricts access to sandbox-related registry keys– Mostly KEY_ALL_ACCESS access• Capability-SID restricts access to Office-related registry keys– Only KEY_READ access– HKCU\Software\Microsoft\Office\15.0\Word\Security\Trusted Locations– HKCU\Software\Microsoft\Office\15.0\Word\File MRULabs.mwrinfosecurity.com | © MWR Labs 20

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!