Full Disclosure mailing list archives
Re: Gates: 'You don't need perfect code' for good security
From: Frank Knobbe <frank () knobbe us>
Date: Sun, 02 Nov 2003 22:50:17 -0600
On Sun, 2003-11-02 at 21:09, Valdis.Kletnieks () vt edu wrote:
On Mon, 03 Nov 2003 12:23:06 +1300, Nick FitzGerald <nick () virus-l demon co uk> said:Finding the actual location of the startup folder was beyond the exploit because it was running in an environment that could not query the registry or other system APIs that would reveal the location.
Actually, I think it was beyond the knowledge of the exploit writer. :)
And for bonus points, explain how you fix the scheme so the poor sysadmin who has to run stuff at startup is able to find the folder, but an exploit running with 'administrator' or 'system' can't find it?
Sure. %SYSTEMROOT%. %WINDIR%, or %USERPROFILE% should work just fine for most cases of scripting and such. Of course viruses and other malware can use the same environment vars. I guess the writers of these annoyances didn't think that far.... lucky us :) Regards, Frank
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- Re: Gates: 'You don't need perfect code' for good security, (continued)
- Re: Gates: 'You don't need perfect code' for good security Geoincidents (Nov 02)
- Re: Gates: 'You don't need perfect code' for good security George Capehart (Nov 03)
- Re: Gates: 'You don't need perfect code' for good security Geoincidents (Nov 03)
- Re: Gates: 'You don't need perfect code' for good security George Capehart (Nov 03)
- Re: Gates: 'You don't need perfect code' for good security Geoincidents (Nov 04)
- Re: Gates: 'You don't need perfect code' for good security Valdis . Kletnieks (Nov 04)
- Re: Gates: 'You don't need perfect code' for good security Dave Howe (Nov 04)
- Re: Gates: 'You don't need perfect code' for good security George Capehart (Nov 04)
- Re: Gates: 'You don't need perfect code' for good security Nick FitzGerald (Nov 02)
- Re: Gates: 'You don't need perfect code' for good security Valdis . Kletnieks (Nov 02)
- Re: Gates: 'You don't need perfect code' for good security Frank Knobbe (Nov 02)
- Re: Gates: 'You don't need perfect code' forgood security Lan Guy (Nov 03)
- Re: Gates: 'You don't need perfect code' for good security Nick FitzGerald (Nov 02)
- Re: Gates: 'You don't need perfect code' for good security Darren Reed (Nov 02)
- Re: Gates: 'You don't need perfect code' for good security Cedric Blancher (Nov 02)
- Re: Gates: 'You don't need perfect code' for good security Valdis . Kletnieks (Nov 03)
- Re: Re: Gates: 'You don't need perfect code' for good security Gary E. Miller (Oct 31)
- Re: Re: Gates: 'You don't need perfect code' for good security Geoincidents (Oct 31)
- Re: Re: Gates: 'You don't need perfect code' for good security Gary E. Miller (Oct 31)