[36157] in bugtraq

home help back first fref pref prev next nref lref last post

Re: First vulnerabilities in the SP2 - XP ?...

daemon@ATHENA.MIT.EDU (Oliver Schneider)
Wed Aug 18 04:51:53 2004

Date: Tue, 17 Aug 2004 18:29:52 +0200 (MEST)
From: "Oliver Schneider" <Borbarad@gmxpro.net>
To: =?ISO-8859-1?Q?=22J=E9r=F4me=22?= ATHIAS <jerome.athias@caramail.com>
Cc: bugtraq@securityfocus.com
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="========GMXBoundary114231092760192"
Message-ID: <11423.1092760192@www41.gmx.net>

This is a MIME encapsulated multipart message -
please use a MIME-compliant e-mail program to open it.

Dies ist eine mehrteilige Nachricht im MIME-Format -
bitte verwenden Sie zum Lesen ein MIME-konformes Mailprogramm.

--========GMXBoundary114231092760192
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit

Hi,

> http://www.heise.de/security/artikel/50051
I also read this yesterday (the German version) and I think it's not a
vulnerability. It's IMO a misconception in the way how SP2 treats alien
executables. And on the other hand it does not actually lower the value of
SP2 concerning security - because the rest of SP2 already boosted security
(this time despite compatibility issues - thanks to MS for finally skipping
compatibility in favor of security). But I agree with the author that MS
should fix this anyway!

Can someone please check if ShellExecute()/ShellExecuteEx() behave different
from the CreateProcess-functions *)? Could that be the reason?
Where is the information stored, that a file was downloaded - ADS? - EAs?
... some arcane new feature?

Oliver

*) CreateProcess, CreateProcessAsUser, CreateProcessWithLogonW,
CreateProcessWithTokenW

-- 
---------------------------------------------------
May the source be with you, stranger ... ;)
--========GMXBoundary114231092760192
Content-Type: text/x-vcard; charset="us-ascii";
 name=""Oliver Schneider"\##\ showdef = 1.vcf"
Content-Transfer-Encoding: 7bit
Content-Disposition: inline; filename=""Oliver Schneider"\##\ showdef = 1.vcf"



--========GMXBoundary114231092760192--


home help back first fref pref prev next nref lref last post