Re: How to Break Windows XP SP2 + Internet Explorer 6 SP2

From: Tod Beardsley (todb_at_PLANB-SECURITY.NET)
Date: 10/27/04

  • Next message: William Lowry: "Logon Hours and Local Admin Equivalence"
    Date:         Wed, 27 Oct 2004 10:38:52 -0500
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Steve Boyce wrote:

    > Disabling ADODB.Connection blocks it, but unfortunately, unlike
    > ADODB.Stream which is rarely used, disabling the connection object will
    > blow holes in a lot of Intranet software (including where I work).

    In environments where ADODB.Connection is important, but this local
    database business is not, you could get a little more surgical and
    merely block ADODB.Recordset.

    OBRegFile:

    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX
    Compatibility\{00000535-0000-0010-8000-00AA006D2EA4}]
    "Compatibility Flags"=dword:00000400

    --
    Tod Beardsley
    --
    NTBugtraq Editor's Note:
    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    --
    

  • Next message: William Lowry: "Logon Hours and Local Admin Equivalence"

    Relevant Pages

    • Re: How to Break Windows XP SP2 + Internet Explorer 6 SP2
      ... In essence this appears to point to 2 holes, ... I don't pretend to understand e. ... f however is a simple workaround for ADODB.Stream inaccessibility, ... disabling the connection object will ...
      (NT-Bugtraq)
    • webdev.webserver fails to start
      ... This included poking a few holes in BlackIce and disabling a ... BlackIce was disabled to no noticeable effect. ...
      (microsoft.public.dotnet.framework.aspnet)