Full Disclosure mailing list archives

Re: Windows XP bug


From: T Biehn <tbiehn () gmail com>
Date: Wed, 7 Jul 2010 15:37:08 -0400

This is fairly classic, not novel.
Your POC is fairly classic, not novel.

-Travis

On Wed, Jul 7, 2010 at 1:54 PM, BlackHawk <hawkgotyou () gmail com> wrote:

Hi list, i recently discovered a very small Windows XP bug, kind of
useless alone but that could be usefull in some scenarios.

Explanation:

when you try to access a non existing directory though shell command
"cd", XP returns an error (obviously), but if you cd to a non-existing
& move one directory up, you'll not get any error.

Example:
---
C:\>cd ./somerandomchars <-- Will give an error
Impossibile trovare il percorso specificato.

C:\>cd ./somerandomchars/../ <-- Everything is ok

C:\>
---

PoC on how to make this thing usefull:

http://www.scribd.com/doc/28080332/Podcast-Generator-1-3-Arbitrary-File-Download-Windows

Hope this could be useful for you in some way..

--
BlackHawk - hawkgotyou () gmail com

Sent with Gmail

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/




-- 
FD1D E574 6CAB 2FAF 2921  F22E B8B7 9D0D 99FF A73C
http://pgp.mit.edu:11371/pks/lookup?search=tbiehn&op=index&fingerprint=on
http://pastebin.com/f6fd606da
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: