[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <dqiv0c$2rt$1@sea.gmane.org>
Date: Tue, 17 Jan 2006 14:29:31 -0000
From: "Dave Korn" <davek_throwaway@...mail.com>
To: full-disclosure@...ts.grok.org.uk
Cc: bugtraq@...urityfocus.com
Subject: Re: WehnTrust - When you have to trust Wehntrust
Thierry Zoller wrote in news:1192877198.20060116214705@...ler.lu
> Dear List,
>
> Small blurp I came around; when Wehntrust creates the autostart key
> it forgets to correctly quote the string in the key and thus may
> trigger an autostart of c:\program.bat|exe|com up-on reboot... [2]
Heh. I _always_ leave copies of calc.exe lying in my root dir, renamed to
"Program.exe" and "Documents.exe".
Starting and stopping RealPlayer leaves you with four instances of calc
running!
Users of Sysinternals' Process Explorer will be amused to see what happens
if they enable Options/Replace Task Manager and then try invoking task
manager from the SAS menu.
cheers,
DaveK
--
Can't think of a witty .sigline today....
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists