Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Does USBPcapCMD.exe need admin rights/privileges to perform USB packet capture #56

Closed
kirankumarg81 opened this issue Aug 9, 2018 · 4 comments

Comments

@kirankumarg81
Copy link

@kirankumarg81 kirankumarg81 commented Aug 9, 2018

Would like to know if USBPcapCMD.exe need admin rights/privileges to perform USB capture.
Platform: Windows-7
USBPcap version: 1.2.0.3

It is installed by Admin and executed by user in my case. Let me know if admin need to set any permissions on USBPcapCMD.exe file.

Thank you.

@desowin

This comment has been minimized.

Copy link
Owner

@desowin desowin commented Aug 10, 2018

The actual capture needs Elevated priviledges. There's no need to set any special permissions on the USBPcapCMD - if you start capture from unelevated USBPcapCMD, it'll automatically display the UAC elevation dialog.

The only reason for the admin rights is to prevent malicious use of the USBPcapDriver (eg. to prevent unelevated viruses from capturing the USB traffic).

@desowin

This comment has been minimized.

Copy link
Owner

@desowin desowin commented Aug 10, 2018

If you run USBPcapCMD as non-admin user, the UAC screen will ask for admin username and password.

@desowin

This comment has been minimized.

Copy link
Owner

@desowin desowin commented Aug 14, 2018

Closing this as this is basic security precaution to require admin rights for capturing on USB devices (USB keyboards are really common nowadays).

@desowin desowin closed this Aug 14, 2018
@kirankumarg81

This comment has been minimized.

Copy link
Author

@kirankumarg81 kirankumarg81 commented Aug 14, 2018

Thanks for the reply, it was very useful.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
2 participants
You can’t perform that action at this time.