Re: strange software > winsupdater.exe

Valdis.Kletnieks_at_vt.edu
Date: 03/17/05

  • Next message: Nick FitzGerald: "Re: strange software > winsupdater.exe"
    To: Harlan Carvey <keydet89@yahoo.com>
    Date: Thu, 17 Mar 2005 13:20:57 -0500
    
    
    

    On Thu, 17 Mar 2005 03:08:14 PST, Harlan Carvey said:

    > However, you _can_ get a warm fuzzy if the file has
    > the MS file version information compiled into it.

    And you verify the authenticity of your warm fuzzy how, exactly?

    const char MS_version[] = "bogus MS file version info goes here";

    (Remember - we've already had major worms that crafted a totally bogus
    "X-Virus: scanned by" header claiming a real AV had scanned it....)

    > That warm fuzzy can be increased if the file is
    > digitally signed by MS.

    First, go back and re-read http://www.cert.org/advisories/CA-2001-04.html

    Second, remember that you're worried that the machine is compromised - and
    you're asking it to verify the signature. Again, if the box is compromised,
    the DLL that verifies signatures could be backdoored as well.

    This is why you *really* need to boot from a known-clean CD and verify the
    signatures from there.

    
    



  • Next message: Nick FitzGerald: "Re: strange software > winsupdater.exe"

    Relevant Pages

    • Re: How to call the SignedData.Verify method
      ... CAPICOM supports both attached and detached signatures. ... For verifying signed data just call verify ... >> How do one call the verify method of SignedData Capicom object? ...
      (microsoft.public.platformsdk.security)
    • Re: About PGP Signing a File.
      ... I have a question regarding signing a file or binary, ... So any place you need to guarantee file integrity you can ... verify their integrity, for example. ... I've also used digital signatures to monitor changes in critical system ...
      (Ubuntu)
    • Re: SignedXml CheckSignature()
      ... A> Can some one verify that .net 2.0 Signatures can not be verified by .net ... With best regards, ... http://www.SecureBlackbox.com - the comprehensive component suite for network security ...
      (microsoft.public.dotnet.framework)
    • Re: Mind has gone blank - how do I do this?
      ... I'd like to know if any other Thunderbird / Enigmail ... users can verify the signatures on my posts:) ...
      (uk.comp.os.linux)
    • Re: Error on FTP Upload .. No such file or directory
      ... his e-mail or use or misuse thereof. ... please verify the authenticity with the! ... sender. ...
      (comp.lang.python)