What is Nostr?
James Forshaw :donor: /
npub1wp4…ejcr
2024-06-05 21:05:23

James Forshaw :donor: on Nostr: Damn, I really thought the Recall database security would at least be, you know, ...

Damn, I really thought the Recall database security would at least be, you know, secure. Turns out Microsoft did pretty much what I blogged about for WindowsApps, except you need to find a specific WIN://SYSAPPID instead. So to bypass the security just get the token for the AIXHost.exe process, then impersonate that and you can access the database, no admin required. Or, as the files are owned by the user, just grant yourself access using icacls etc :D
Author Public Key
npub1wp4gyc9xmkjxl0vpxpmv0hmsw25uyhvwnynewn5mrj8s66v8ku6sesejcr