BugTraq
Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 06:24PM
Disclosure From OSSI (disclosure ossecurity ca) (4 replies)
RE: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 10:42PM
Oliver Lavery (olavery pivx com)
RE: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 10:01PM
David Schwartz (davids webmaster com) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 03:51AM
Darren Reed (avalon caligula anu edu au) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 09:10PM
der Mouse (mouse Rodents Montreal QC CA) (3 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 06:11AM
Darren Reed (avalon caligula anu edu au) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 07:07AM
der Mouse (mouse Rodents Montreal QC CA) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 08:44AM
Darren Reed (avalon caligula anu edu au) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 09:03AM
der Mouse (mouse Rodents Montreal QC CA)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 04:04AM
Glynn Clements (glynn clements virgin net)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 12:28AM
John D. Hardin (jhardin impsec org) (1 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 11 2004 04:56AM
der Mouse (mouse Rodents Montreal QC CA)
RE: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 07:31PM
Ward Taylor (rfdhomer windyplains com) (2 replies)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 04:40PM
Nexus (nexus patrol i-way co uk)
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 10 2004 10:31AM
Peter Pentchev (roam ringlet net)
On Mon, Feb 09, 2004 at 01:31:25PM -0600, Ward Taylor wrote:
> Hi:
> There is a win2k registry setting which allows the default .dll search order
> to be changed.
> Key:
> HKLM\SYSTEM\CurrentControlSet\Control\SessionManager
> Value Name:
> SafeDllSearchMode
> Data:
> 0x1

Yeah, but won't this break a lot of programs that install their DLL's in
their own directories by design, so that they may be installed by users
without administrative privileges on older versions of Windows? I know
that Windows XP "shadows" %WINDIR% under "Documents and
Settings\username", but this is a recent development, and there are
still an awful lot of programs which rely on the 'program directory
first' search order.

G'luck,
Peter

--
Peter Pentchev roam (at) ringlet (dot) net [email concealed] roam (at) sbnd (dot) net [email concealed] roam (at) FreeBSD (dot) org [email concealed]
PGP key: http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint FDBA FD79 C26F 3C51 C95E DF9E ED18 B68D 1619 4553
This sentence every third, but it still comprehensible.

[ reply ]
Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer Feb 09 2004 07:20PM
Seth Arnold (sarnold wirex com)


 

Privacy Statement
Copyright 2010, SecurityFocus