RE: [Full-Disclosure] What about M$ in the shell: race

From: Larry Seltzer (larry_at_larryseltzer.com)
Date: 07/10/04

  • Next message: Perrymon, Josh L.: "RE: [Full-Disclosure] What about M$ in the shell: race"
    To: <1@malware.com>, <full-disclosure@lists.netsys.com>
    Date: Sat, 10 Jul 2004 14:08:29 -0400
    
    

    >>http://poc.homedns.org/execute.htm
    >>http://62.131.86.111/security/idiots/malware2k/installer.htm

    I don't think of the Shell.Application exploit as the same thing as the shell: link
    exploit. Am I missing something?

    >>shell:desktop

    This really doesn't impress me. I don't see this as an attack at all, unless you can
    find a way to overflow the folder or something like that. Can you actually run code this
    way, as was easy to do with Mozilla with a simple shell:folder\\foo.exe?

    Larry Seltzer
    eWEEK.com Security Center Editor
    http://security.eweek.com/
    http://blog.ziffdavis.com/seltzer
    larryseltzer@ziffdavis.com

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Perrymon, Josh L.: "RE: [Full-Disclosure] What about M$ in the shell: race"

    Relevant Pages

    • Israel: 2 down, 1 to go.
      ... respectable temper or shell, and she'll nevertheless impress everybody. ... All silks genuinely fulfil the worthwhile autumn. ...
      (rec.music.christian)
    • Re: COM3-14
      ... I'm running with a command line shell. ... I can run 'regedit' and it brings up a GUI screen, ... The only help files I see missing are for the video driver and I'm not worried about ... this configuration" flag in the Configuration ...
      (microsoft.public.windowsxp.embedded)
    • Re: killed libc.so.7 somehow - help./ISO images of CURRENT
      ... When booting in single user mode, use /rescue/sh as initial shell. ... since cc was missing on the boot/rescue cd. ...
      (freebsd-current)
    • Re: ls recursively?
      ... On 2005-04-22, larzeb wrote: ... > What am I missing? ... the point is that *vb is expanded by the shell and then ... NT is a server with a "Kick me" sign taped to it. ...
      (comp.os.linux.misc)
    • Re: how to get the hostnames and memory usage biger than 30M?
      ... On Tuesday 15 April 2008 21:43, Bill Marcum wrote: ... I know AWK can do this, but I just want to use shell. ... You are missing a "fi". ...
      (comp.unix.shell)