Re: Rather large MSIE-hole

From: Syzop (syzat_private)
Date: Thu Mar 14 2002 - 11:39:20 PST

  • Next message: Dave Aitel: "Re: idq.dll problem??"

    Hi,
    
    Maarten Oosterink wrote:
    
    > I can image commands like
    > 'net send * w00t w00t' being funny, but 'format c: /autotest' isn't.
    
    <offtopic>
    I know this is unrelated but... This is the Xth time I see this here (and at bugtraq):
    you can't just run a "format c:" if your C drive is in use (in windoze) because your
    drive is locked, yes I tried this at my own computer both with w98 and w2k.
    Ofcouse this doesn't mean other dangerous commands work like RD /Q /S c:\
     in NT/W2K (rm -rf / in windoze-style).
    </offtopic>
    
    I wasn't able to pass commands and also UNC paths (\\\\IP\\SHARE\\FILE) don't
    work because you then get a "your current security settings dont allow this blabla".
    
        Syzop.
    



    This archive was generated by hypermail 2b30 : Thu Mar 14 2002 - 14:05:46 PST