lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
From: bkfsec at sdf.lonestar.org (Barry Fitzgerald)
Subject: Re: shell:windows

Larry Seltzer wrote:

>
>meaningful problem either, then we can agree to disagree on the scope.  I'll agree that
>getting this issue to run code of the choosing of the attacker is more difficult than
>some other unpatched IE holes, but it is not impossible. 
>
>I disagree completely. The Mozilla problem, which I'll readily agree is not in the same
>league with most of the recent IE problems, allowed a local program to execute simply by
>visiting a web page that had the appropriate shell: link in a META tag. You actually
>think this is on the same level as requiring a user to type
>"shell:windows\system32\foo.exe" into the Address bar?
>
>
>  
>
No - there are numerous ways to force input into places like the address 
bar.  As someone else already stated, for this to work you have to be 
able to push it into that area.  There are numerous ways to do this and 
for a person with a little more time on their hands, finding one that 
works properly should not be difficult.

Stop thinking about this as being a one-dimensional issue.  Security 
issues very rarely are that one-dimensional. 

             -Barry


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ