Re: Win32 vulnerability? Or application vulnerability?
From: Deus, Attonbitus (Thor@HAMMEROFGOD.COM)Date: 08/08/02
- Previous message: Chris Paget: "Re: Win32 vulnerability? Or application vulnerability?"
- In reply to: Chris Paget: "Re: Win32 vulnerability? Or application vulnerability?"
- Next in thread: Mike Murray: "Re: Win32 vulnerability? Or application vulnerability?"
- Next in thread: Stephen D. B. Wolthusen: "Re: Win32 vulnerability? Or application vulnerability?"
- Reply: Mike Murray: "Re: Win32 vulnerability? Or application vulnerability?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 8 Aug 2002 09:14:57 -0700 From: "Deus, Attonbitus" <Thor@HAMMEROFGOD.COM> To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
At 07:28 AM 8/8/2002, Chris Paget wrote:
>The scenario: A user has a Windows 2000 box running a personal
>firewall. The firewall only "trusts" Internet Explorer to access the
>Internet.
>
>Somehow or other, some malicious code gets onto the system. It fires
>up an IE window, and makes it invisible. It injects a DDoS client (or
>whatever) into IE, using exactly the same technique described in my
>paper. That malicious code within IE then accesses the network
>freely, since the personal firewall can't tell the difference. It
>could even send out its traffic as legitimate HTTP requests, so that
>it is more or less untraceable.
<snip>
Not withstanding the implications of exploiting privileged services, one
really has to question the validity of any exploit that first requires
malicious code to get onto the system. Why worry about firing up an IE
window when you can load a kernel mode driver? If they run our code, then
we immediately own the box.
I honestly feel any sentence that starts out "If you can get your code on
the box..." must end in a ".. then nothing else matters."
Cheers,
AD
- Previous message: Chris Paget: "Re: Win32 vulnerability? Or application vulnerability?"
- In reply to: Chris Paget: "Re: Win32 vulnerability? Or application vulnerability?"
- Next in thread: Mike Murray: "Re: Win32 vulnerability? Or application vulnerability?"
- Next in thread: Stephen D. B. Wolthusen: "Re: Win32 vulnerability? Or application vulnerability?"
- Reply: Mike Murray: "Re: Win32 vulnerability? Or application vulnerability?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|