lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20040210103119.GD738@straylight.m.ringlet.net>
Date: Tue, 10 Feb 2004 12:31:19 +0200
From: Peter Pentchev <roam@...glet.net>
To: Ward Taylor <rfdhomer@...dyplains.com>
Cc: bugtraq@...urityfocus.com
Subject: Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer

On Mon, Feb 09, 2004 at 01:31:25PM -0600, Ward Taylor wrote:
> Hi:
> There is a win2k registry setting which allows the default .dll search order
> to be changed.
> Key:
> HKLM\SYSTEM\CurrentControlSet\Control\SessionManager
> Value Name:
> SafeDllSearchMode
> Data:
> 0x1

Yeah, but won't this break a lot of programs that install their DLL's in
their own directories by design, so that they may be installed by users
without administrative privileges on older versions of Windows?  I know
that Windows XP "shadows" %WINDIR% under "Documents and
Settings\username", but this is a recent development, and there are
still an awful lot of programs which rely on the 'program directory
first' search order.

G'luck,
Peter

-- 
Peter Pentchev	roam@...glet.net    roam@...d.net    roam@...eBSD.org
PGP key:	http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint	FDBA FD79 C26F 3C51 C95E  DF9E ED18 B68D 1619 4553
This sentence every third, but it still comprehensible.

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ