aboutsummaryrefslogtreecommitdiffstatshomepage
path: root/attacksurface.md (follow)
Commit message (Collapse)AuthorAgeFilesLines
* tunnel: retain SeLoadDriverPrivilegeJason A. Donenfeld2019-06-071-1/+1
| | | | This is a big loss. We'll need to revisit this.
* global: several helpers are now upstreamJason A. Donenfeld2019-05-271-1/+1
|
* ui: drop permissionsJason A. Donenfeld2019-05-151-0/+1
|
* service: move WTS upstreamJason A. Donenfeld2019-05-151-1/+1
|
* service: clean up token manglingJason A. Donenfeld2019-05-141-1/+1
|
* attacksurface: updatesJason A. Donenfeld2019-05-131-5/+4
|
* service: use more standard naming scheme for syscallsJason A. Donenfeld2019-05-131-1/+1
|
* service: run UI with elevated tokenJason A. Donenfeld2019-05-121-6/+4
| | | | | There are too many attacks possible when starting this with a non-elevated token.
* service: run UI at high integrityJason A. Donenfeld2019-05-111-0/+1
|
* service: local system's token is a bit more locked down than elevatedJason A. Donenfeld2019-05-081-4/+4
|
* attacksurface: update with latest infoJason A. Donenfeld2019-05-071-10/+2
|
* updater: move into managerJason A. Donenfeld2019-05-061-1/+1
|
* service: set security attributes on new processJason A. Donenfeld2019-05-021-1/+3
|
* version: add certificate checking for official versionsJason A. Donenfeld2019-04-301-1/+1
| | | | This is an easy circumventable check designed mostly for convenience.
* version: add beginnings of authenticode checkingJason A. Donenfeld2019-04-301-0/+11
|
* service: use WireGuardTunnel$ prefixJason A. Donenfeld2019-04-051-1/+1
|
* attacksurface: add descriptionsJason A. Donenfeld2019-04-021-0/+40