Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Hidden-code flaw in Windows renews worries over stealthly malware
Robert Lemos, SecurityFocus 2005-08-31

A flaw in the way that several security programs and systems utilities detect system changes could allow spyware to spread surreptitiously and have renewed worries about stealthier attack code.

Comments Mode:
Please explain... 2005-08-31
Brian M. Thomas (5 replies)
Re: Please explain... 2005-08-31
Anonymous (1 replies)
Re: Re: Please explain... 2005-09-02
Anonymous
You have to remember that registry keys are not the same as filenames. Even if they were, the length of file names are not limited by the OS, but by the file system. The registry is a binary file, of which the format was chosen at design time.

Anyway, it sounds to me the issue is with certain client software attempting to read key data, and simply failing to display a key longer than 256 bytes. In turn this would allow certain active keys to be 'hidden' from any client, be it an editor or a spyware removal tool. So, while it hurts me to say this, Microsoft may be right that it is not an issue with the OS.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11300/32380#32380
Re: Please explain... 2005-08-31
Anonymous (1 replies)
Re: Re: Please explain... 2005-09-12
Anonymous
Re: Please explain... 2005-08-31
Anonymous
Re: Please explain... 2005-09-05
Anonymous
Flypaper? 2005-09-05
Anonymous (1 replies)
Re: Flypaper? 2005-09-08
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus