[33566] in bugtraq

home help back first fref pref prev next nref lref last post

Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer

daemon@ATHENA.MIT.EDU (Peter Pentchev)
Tue Feb 10 12:34:43 2004

Date: Tue, 10 Feb 2004 12:31:19 +0200
From: Peter Pentchev <roam@ringlet.net>
To: Ward Taylor <rfdhomer@windyplains.com>
Cc: bugtraq@securityfocus.com
Message-ID: <20040210103119.GD738@straylight.m.ringlet.net>
Mail-Followup-To: Ward Taylor <rfdhomer@windyplains.com>,
	bugtraq@securityfocus.com
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="mP3DRpeJDSE+ciuQ"
Content-Disposition: inline
In-Reply-To: <BJEIIGDJCBPHLGHHKGJFCECLCPAA.rfdhomer@windyplains.com>

--mP3DRpeJDSE+ciuQ
Content-Type: text/plain; charset=windows-1251
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, Feb 09, 2004 at 01:31:25PM -0600, Ward Taylor wrote:
> Hi:
> There is a win2k registry setting which allows the default .dll search or=
der
> to be changed.
> Key:
> HKLM\SYSTEM\CurrentControlSet\Control\SessionManager
> Value Name:
> SafeDllSearchMode
> Data:
> 0x1

Yeah, but won't this break a lot of programs that install their DLL's in
their own directories by design, so that they may be installed by users
without administrative privileges on older versions of Windows?  I know
that Windows XP "shadows" %WINDIR% under "Documents and
Settings\username", but this is a recent development, and there are
still an awful lot of programs which rely on the 'program directory
first' search order.

G'luck,
Peter

--=20
Peter Pentchev	roam@ringlet.net    roam@sbnd.net    roam@FreeBSD.org
PGP key:	http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint	FDBA FD79 C26F 3C51 C95E  DF9E ED18 B68D 1619 4553
This sentence every third, but it still comprehensible.

--mP3DRpeJDSE+ciuQ
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (FreeBSD)

iD8DBQFAKLL37Ri2jRYZRVMRAhM6AJ9XXHDw3jVFXXPzuflpOUhnBxrFOwCgsqV/
VEXqq5Cqdvg8PA+jA+2PjoI=
=C8mj
-----END PGP SIGNATURE-----

--mP3DRpeJDSE+ciuQ--

home help back first fref pref prev next nref lref last post