Vulnerability Development mailing list archives

Re: How to hide a file ?


From: "J. J. Horner" <jhorner () 2jnetworks com>
Date: Wed, 9 Jan 2002 12:15:15 -0500

* H C (keydet89 () yahoo com) [020109 11:51]:

Also keep in mind that:
(a) applications that only *read* the file contents,
such as graphics and multimedia viewers, don't usually
execute any arbitrary data they find in, or associated
with, the file.


I was thinking of the recent Windows Media player vulnerability
where an executable was given the correct MIME type to call
Windows Media player so it could be exploited.  If this
is possible on an NTFS partition where an application is
associated with IE and IE had an exploitable vulnerability,
it is theoretically not impossible.

An application that reads data from a file must also 
be able to act upon that data.  If the data includes encoding
that can exploit a weakness, just "reading" data doesn't help.

Thanks,
JJ

-- 
J. J. Horner
"H*","6a686f726e657240326a6e6574776f726b732e636f6d"
***************************************************
"H*","6a6a686f726e65724062656c6c736f7574682e6e6574"

Freedom is an all-or-nothing proposition:  either we 
are completely free, or we are subjects of a
tyrannical system.  If we lose one freedom in a
thousand, we become completely subjugated.

Attachment: _bin
Description:


Current thread: