[40276] in bugtraq
Re: anti Windows XP SP2 firewall trick
daemon@ATHENA.MIT.EDU (Ansgar -59cobalt- Wiechers)
Tue Sep 13 12:47:00 2005
Date: Thu, 8 Sep 2005 15:00:47 +0200
From: Ansgar -59cobalt- Wiechers <bugtraq@planetcobalt.net>
To: bugtraq@securityfocus.com
Message-ID: <20050908150047.B1184@planetcobalt.net>
Mail-Followup-To: bugtraq@securityfocus.com
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20050907203450.2196.qmail@securityfocus.com>; from crusoe@alexandria.cc on Wed, Sep 07, 2005 at 08:34:50PM -0000
Resent-From: cobalt@planetcobalt.net
Resent-To: bugtraq@securityfocus.com
On 2005-09-07 crusoe@alexandria.cc wrote:
[...]
> #c:\bugg.exe Server running on port 2001
>
> connect to server with :
>
> #telnet localhost 2001
[...]
> Our Registry path is
>
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
>
> and there you can create string value
>
> Value name Value
>
> C:\chat.exe ........ C:\chat.exe:*:Enabled:chat
Being able to create that value means that you have admin privileges on
that box, thus you can do whatever you want anyway (including completely
shutting down the Windows-Firewall). So this is by no means a trick or
flaw, but simply expected behaviour.
Regards
Ansgar Wiechers
--
"Another option [for defragmentation] is to back up your important files,
erase the hard disk, then reinstall Mac OS X and your backed up files."
--http://docs.info.apple.com/article.html?artnum=25668