Re: [Full-disclosure] Miscrosoft Registry Editor 5.1/XP/2K long string key vulnerability

From: Spiro Trikaliotis (trik-news_at_gmx.de)
Date: 08/24/05

  • Next message: Kaveh Razavi: "[Full-disclosure] Re: LeapFTP .lsq Buffer Overflow Vulnerability"
    Date: Wed, 24 Aug 2005 20:17:07 +0200
    To: full-disclosure@lists.grok.org.uk
    
    

    Hello,

    * On Wed, Aug 24, 2005 at 11:01:11AM +0400 Igor Franchuk wrote:
     
    > DESCRIPTION
    >
    > Microsoft Registry Editor for 2K and XP (Regedt32.exe) has a nice design flow
    > that is naturally allows to hide registry information from viewing and
    > editing even from users with administrative access. (really handful, thanks guys)

    this somehow reminds me of

      http://www.sysinternals.com/Information/TipsAndTrivia.html#HiddenKeys

    Of course, I am well aware that these both are different.

    Anyway, I'm not sure if the one or the other can be called a "security
    bug".

    Best regards,
       Spiro.
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/


  • Next message: Kaveh Razavi: "[Full-disclosure] Re: LeapFTP .lsq Buffer Overflow Vulnerability"

    Relevant Pages

    • Re: Opening Files
      ... I would agree for editing a document, but not for viewing ... viewing only and not prompt the user to download if they ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Worthwhile for LaTeX users to use Lyx?
      ... the formatting commands are distracting, ... viewing from editing is highly nonideal for composition. ... then when you get to a certain point, you switch back to the LaTeX text ...
      (comp.text.tex)
    • Re: Opening Files
      ... >This is a setting that can be changed in Windows Explorer: ... >> viewing only and not prompt the user to download if they ... >> aren't editing. ...
      (microsoft.public.sharepoint.windowsservices)
    • Re: Brexx function libraries for data entry on the Unix console
      ... viewing, entry and editing of multiple line text viewing and editing ... Mark Hobley ... Regina and ooRexx support the SAA API. ...
      (comp.lang.rexx)
    • Re: Prevent terminal/screen refresh after using "man" or "vi"
      ... > up a man page, or edit a file in vi, when you quit vi or the man page, ... > you were viewing or the file you were editing is displayed on the pterminal ... I suggest you try using Emacs shell mode for interacting with the shell, ...
      (comp.os.linux.questions)