|
Full Disclosure
mailing list archives
Re: Miscrosoft Registry Editor 5.1/XP/2K long string key vulnerability
From: "mike king" <ngiles () hushmail com>
Date: Wed, 24 Aug 2005 21:38:06 -0700
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I didnt see anyone post a way to delete the registry key added so
here is the tool I found that can accomplish this.
"Regalyzer" from http://www.safer-
networking.org/en/download/index.html
query the key added to the registry.
E:\>reg query HKEY_LOCAL_MACHINE\SOFTWARE\empty
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\empty
helloworldhelloworldhelloworldhelloworldhelloworldhelloworldhellowor
ldhelloworldhelloworldhelloworldhelloworldhellow
orldhelloworldhelloworldhelloworldhelloworldhelloworldhelloworldhell
oworldhelloworldhelloworldhelloworldhelloworldhellow
orldhelloworldhelloworl REG_SZ
E:\ >
After removing the key from the registry with Reglyzer
E:\ reg query HKEY_LOCAL_MACHINE\SOFTWARE\empty
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\empty
E:\ >
Best of luck mike king
time® is a trademark of Universe©
Public use permited by fair use agreement ( copyright [NULL] )
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.4
wkYEARECAAYFAkMNSykACgkQUjm7xSZSd8FxBgCgkxvav4tmXZY5te5K2hCNPmHekV4A
nRGuGi5KnT0tNLvLSIP7HSCFaQyi
=uvzy
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
By Date
By Thread
Current thread:
- Re: Miscrosoft Registry Editor 5.1/XP/2K long string key vulnerability mike king (Aug 24)
|