sn.exe -Vr assembly

From: Gecko (nada_at_nada.com)
Date: 01/20/05


Date: Thu, 20 Jan 2005 13:02:00 -0600

Is it possible for a hacker to run the strong name utility on a client
computer with the -Vr parameter to skip verification of *signed* assemblies
installed in the client computer rendering my whole strong name security
scenario useless?

Since most people are usually logged as Administrators, if I was a
disgruntled ex-employee and wanted to do some damage to my ex-employer, it
seems to me like if I could run the sn.exe utility on the client computer to
skip verification of the assemblies that I know my employer distributes and
replace them with my own and I could easily cause some good damage in the
name of my ex-employer.

I am still too new to this strong naming thing so forgive me if the question
is a silly one, thanks.



Relevant Pages

  • Re: soapsuds
    ... > the 'server' assembly, then the soapsuds extraction falls over. ... > in .Net that namespaces cannot span assemblies? ... > interface defined in a shared assembly (which can be implemented my other ... dll which sits both on the server and the client allowing objects to talk to ...
    (microsoft.public.dotnet.framework.remoting)
  • Re: "Insufficient state to deserialize the object" error
    ... The delegate itself is a serializable object, so both client and server need ... > that requires serialization? ... >> If any of the assemblies are being loaded from the mapped drive, ...
    (microsoft.public.dotnet.framework.remoting)
  • Re: Can RCW and CCW be used together?
    ... component project reference to my client project and build. ... Dim iads As IadsAutomationLib.Application ... problem-domain specific assemblies and the assemblies for the RCW-Interop ...
    (microsoft.public.dotnet.framework.interop)
  • Re: Natural keys vs Aritficial Keys
    ... A welding shop client that empoyed hundreds of welders built and assembled very ... complex piping assemblies for refineries, power plants and oil sands plants. ... When a designer is exposed to this, a moment's thought should be enough to see that the different parties operate from distinct concepts. ...
    (comp.databases.theory)
  • No-Touch deployment - IEExec - Duplicate Entries in Assembly Cache - Strongly Typed Datasets - Inval
    ... I've been struggling with a problem using No-Touch Deployment for 10 ... The client is a VB.NET winform ... the client app on the server and run it from within Internet Explorer. ... Assemblies deployed with IE are downloaded multiple times? ...
    (microsoft.public.dotnet.framework.windowsforms)