[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <ehnnlt$e2a$1@sea.gmane.org>
Date: Wed, 25 Oct 2006 14:09:14 +0100
From: "Dave \"No, not that one\" Korn" <davek_throwaway@...mail.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: Windows Command Processor
CMD.EXEBufferOverflow
Peter Ferrie wrote:
>>> file://
>>> ?
>>
>> OK, I'll bite. Why are file:// URLs relevant to the discussion?
>
> It allows arbitrary data to be passed to CMD.EXE, without first
> owning the system.
No it doesn't. It passes arbitrary data to the windows gui shell exec
function. It doesn't invoke cmd.exe. Unless you have an actual working
example?
cheers,
DaveK
--
Can't think of a witty .sigline today....
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists