Test your windows OS

From: Berend-Jan Wever (skylined_at_edup.tudelft.nl)
Date: 10/05/04

  • Next message: Alexander Antipov: "[MAXPATROL Security Advisories] Cross site scripting in Invision Power Board"
    To: <bugtraq@securityfocus.com>
    Date: Tue, 5 Oct 2004 01:09:58 +0200
    
    

    Hi all,

    Wanna do a quick test to see if the programmers that wrote your windows operating system have any clue as to what there doing ? Run these commands from cmd.exe in the system32 directory:

    for %i in (*.exe) do start %i %n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n%n
    for %i in (*.exe) do start %i AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA.... (type as much "A"-s as cmd.exe allows on one line.)

    Each command will execute every program in your system32 directory, most of them will either ignore the parameter or report an error because the parameter doesn't make sence... But on my win2k system I found 6 programs vulnerable to these very simple formatsting and BoF tests.... grpconv even gives EIP 0x00410041, can it be any easier?

    These are not vulnerabilities in itself: you cannot gain access or elevate priviledges but I just wanted to let you know that these programmers did a sloppy job.

    Cheers,
    SkyLined


  • Next message: Alexander Antipov: "[MAXPATROL Security Advisories] Cross site scripting in Invision Power Board"

    Relevant Pages

    • [Full-Disclosure] Test your windows OS
      ... Wanna do a quick test to see if the programmers that wrote your windows operating system have any clue as to what there doing? ... These are not vulnerabilities in itself: you cannot gain access or elevate priviledges but I just wanted to let you know that these programmers did a sloppy job. ...
      (Full-Disclosure)
    • Re: Jobs using C
      ... > I was wondering what the current job opportunities in C are these days. ... > What jobs do C programmers hold? ... Erik de Castro Lopo nospam@mega-nerd.com ... Microsoft is finally bringing all of its Windows operating system families ...
      (comp.lang.c)
    • .NET observations
      ... The front page of this site had nearly 600 HTML validation errors (and they ... This platform seems to exist solely to shield developers from HTML tags, ... just as VB and data-bound grids exist to shield "programmers" from coding. ... haven't a clue about HTML, email, JavaScript or anything else Web-related. ...
      (microsoft.public.dotnet.framework.aspnet)
    • thanks
      ... i just wanna say that free bsd rocks ... and that the programmers of this operatings system and all ...
      (freebsd-questions)
    • Re: Native Code vs PCode OT
      ... >>I really miss the old days when most 'programmers' did not have a clue ... > Some would call that the very definition of "cowboy coder" ... Yeeeha! ...
      (microsoft.public.vb.general.discussion)