Re: anti Windows XP SP2 firewall trick
From: Ansgar -59cobalt- Wiechers (bugtraq_at_planetcobalt.net)
Date: 09/08/05
- Previous message: Mandriva Security Team: "MDKSA-2005:163 - Updated MySQL packages fix vulnerability"
- In reply to: crusoe_at_alexandria.cc: "anti Windows XP SP2 firewall trick"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 8 Sep 2005 15:00:47 +0200 To: bugtraq@securityfocus.com
On 2005-09-07 crusoe@alexandria.cc wrote:
[...]
> #c:\bugg.exe Server running on port 2001
>
> connect to server with :
>
> #telnet localhost 2001
[...]
> Our Registry path is
>
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
>
> and there you can create string value
>
> Value name Value
>
> C:\chat.exe ........ C:\chat.exe:*:Enabled:chat
Being able to create that value means that you have admin privileges on
that box, thus you can do whatever you want anyway (including completely
shutting down the Windows-Firewall). So this is by no means a trick or
flaw, but simply expected behaviour.
Regards
Ansgar Wiechers
-- "Another option [for defragmentation] is to back up your important files, erase the hard disk, then reinstall Mac OS X and your backed up files." --http://docs.info.apple.com/article.html?artnum=25668
- Previous message: Mandriva Security Team: "MDKSA-2005:163 - Updated MySQL packages fix vulnerability"
- In reply to: crusoe_at_alexandria.cc: "anti Windows XP SP2 firewall trick"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|