Re: Fixable

From: Alun Jones (alun@texis.com)
Date: 08/23/02


From: alun@texis.com (Alun Jones)
Date: Thu, 22 Aug 2002 22:09:44 GMT

In article <ak3600$ifu$6@sapa.inka.de>, Bernd Eckenfels
<ecki-news2002-08@lina.inka.de> wrote:
>In comp.security.misc Ted Beverley <tb@bh.com> wrote:
>> Adding the following code will prevent shatter from working.
>
>you have to add this to all programs on your desktop. Thats the problem, an
>admin cant do that on his box, therefore he will be most likely vulnerable
>to the shattner attack for month or years.

No, you have to add that to the few programs that are supposedly secured,
high-privilege applications that just feel like they absolutely _have_ to
interact with the user.

Of course, a first approximation to that is all of the services that are
installed to "Interact with desktop".

Alun.
~~~~

[Please don't email posters, if a Usenet response is appropriate.]

-- 
Texas Imperial Software   | Try WFTPD, the Windows FTP Server. Find us at
1602 Harvest Moon Place   | http://www.wftpd.com or email alun@texis.com
Cedar Park TX 78613-1419  | VISA/MC accepted.  NT-based sites, be sure to
Fax/Voice +1(512)258-9858 | read details of WFTPD Pro for XP/2000/NT.



Relevant Pages

  • Re: Fixable
    ... Thats the problem, an ... >admin cant do that on his box, therefore he will be most likely vulnerable ... installed to "Interact with desktop". ... Fax/Voice +1258-9858 | read details of WFTPD Pro for XP/2000/NT. ...
    (comp.security.misc)
  • Re: Counter in DataReport
    ... code in this and thats what my doubt was whether can v able to interact ... Dim rst As New Recordset ... Prev by Date: ...
    (microsoft.public.vb.general.discussion)
  • RE: as/400
    ... In which way do you mean interact? ... If thats the case you may be able to get third party drivers for ... client access, this should allow you to use ado/asp.net to interact with your ...
    (microsoft.public.dotnet.general)