Re: Execution Rights Not Checked Correctly For 16-bit Applications

From: Torbjörn Hovmark (torbjorn.hovmarkat_private)
Date: Thu Sep 19 2002 - 00:04:19 PDT

  • Next message: Ofir Arkin: "The Trivial Cisco IP Phones Compromise"

    Steve,
    
    > I wasn't able to duplicate this on a Windows 2000 SP3 box. I think
    > it may have been fixed there, seeing as this document was written
    > before SP3 was released.
    
    No, it isn't fixed in SP3. Microsoft has indicated that they will fix it in
    SP4.
    
    Besides, when trying to duplicate this, make sure that you don't
    accidentally deny or remove read permission for the file as well. If you do,
    NTVDM will not be able to read the file into memory. (I don't know if this
    is the reason you can't duplicate it, but it seems to be a common mistake.)
    
    
    Best regards / Torbjörn Hovmark
    
    ______________________________________
    Abtrusion Security AB
    http://www.abtrusion.com
    



    This archive was generated by hypermail 2b30 : Thu Sep 19 2002 - 07:35:31 PDT