lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite for Android: free password hash cracker in your pocket
[<prev] [next>] [day] [month] [year] [list]
Date: Mon, 16 Jan 2006 19:16:05 -0500
From: "Paul" <pvnick@...il.com>
To: <bugtraq@...urityfocus.com>,
	<full-disclosure@...ts.grok.org.uk>
Subject: Sun Java Update Scheduler gets placed in
	autostart without absolute path quotes

Name: SunJavaUpdateSched

Value: C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe

 

…Meaning that Windows will attempt to execute C:\Program.exe first, and then
the rest of the path if that doesn’t exist.

 

Might be a bug in the old version – I haven’t updated yet. Not a very
critical bug, although the autostart is in HKLM, so users can install
malware on other users’ accounts.

 

Kind regards,

Paul Nickerson

Greyhats Security


-- 
No virus found in this outgoing message.
Checked by AVG Free Edition.
Version: 7.1.375 / Virus Database: 267.14.19/231 - Release Date: 1/16/2006
 

Content of type "text/html" skipped

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ