[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <b1fed46e0805141349j3cb92d2fxa0dd066978b73a78@mail.gmail.com>
Date: Wed, 14 May 2008 13:49:35 -0700
From: "Peter Ferrie" <peter.ferrie@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: [Wired Security/EOF] Disable Windows Defender
(Vista) PoC code
> my friend Izee from the EOF-Project(.net) team has coded a
> simple PoC code, that demonstrates how to disable the Windows
> Defender on Vista (tested with and without SPs on x86/x64)
> using its own API made for it.
Does he realise that he must be Admin first?
Then he he can just disable the service, or delete the files, or whatever.
Using the API doesn't gain much here.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists