Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: Round One: "DLL Proxy" Attack Easily Hijacks SSL from Internet Explorer
From: Peter Pentchev <roam () ringlet net>
Date: Tue, 10 Feb 2004 12:31:19 +0200

On Mon, Feb 09, 2004 at 01:31:25PM -0600, Ward Taylor wrote:
Hi:
There is a win2k registry setting which allows the default .dll search order
to be changed.
Key:
HKLM\SYSTEM\CurrentControlSet\Control\SessionManager
Value Name:
SafeDllSearchMode
Data:
0x1

Yeah, but won't this break a lot of programs that install their DLL's in
their own directories by design, so that they may be installed by users
without administrative privileges on older versions of Windows?  I know
that Windows XP "shadows" %WINDIR% under "Documents and
Settings\username", but this is a recent development, and there are
still an awful lot of programs which rely on the 'program directory
first' search order.

G'luck,
Peter

-- 
Peter Pentchev  roam () ringlet net    roam () sbnd net    roam () FreeBSD org
PGP key:        http://people.FreeBSD.org/~roam/roam.key.asc
Key fingerprint FDBA FD79 C26F 3C51 C95E  DF9E ED18 B68D 1619 4553
This sentence every third, but it still comprehensible.

Attachment: _bin
Description:


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]