ISA Firewall client. Traffic interception from local system account.
hi!
isa firewall client can intercept users traffic , bypass proxy. ok standart interactive launch of application.
when start app system account role - won't work :(
with procexp can see fwcwsp.dll injection, nothing happens.
of course can write rules isa server intercept data .exe, there other ideas? i'm intrested in how ammyy admin, started @ system account works properly?
can thread impersonation me? , if - doing wrong:
1. im getting token with wtsqueryusertoken of current session
2. duplicatetokenex token primary
3. run creating sockets , network connection in impersonated context.
on re-reading, appears op needs writing rule isa server allow traffic.
i'd suggest asking in forefront threat management gateway forum. tmg replaced isa time ago.
karl
when see answers , helpful posts, please click vote helpful, propose answer, and/or mark answer.
blog: unlock powershell
book: windows powershell 2.0 bible
e-mail: -join('6d73646e5f6b61726c406f75746c6f6f6b2e636f6d'-split'(?<=\g.{2})'|%{if($_){[char][int]"0x$_"}})
Visual Studio Languages , .NET Framework > Visual C#
Comments
Post a Comment