Full Disclosure mailing list archives

Re: Re: Miscrosoft Registry Editor 5.1/XP/2K long string key vulnerability


From: Micheal Espinola Jr <michealespinola () gmail com>
Date: Thu, 25 Aug 2005 09:56:46 -0400

You can remove a registry key easily without the need of a 3rd party app.

"To delete a registry key with a .reg file, put a hyphen (-) in front
of the RegistryPath in the .reg file."

http://support.microsoft.com/default.aspx?scid=kb;en-us;310516&sd=tech


On 8/25/05, mike king <ngiles () hushmail com> wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

I didn't see anyone post a way to delete the registry key added so
here is the tool I found that can accomplish this.

"Regalyzer" from http://www.safer-
networking.org/en/download/index.html

query the key added to the registry.

E:\>reg query HKEY_LOCAL_MACHINE\SOFTWARE\empty

! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\empty
helloworldhelloworldhelloworldhelloworldhelloworldhelloworldhellowor
ldhelloworldhelloworldhelloworldhelloworldhellow
orldhelloworldhelloworldhelloworldhelloworldhelloworldhelloworldhell
oworldhelloworldhelloworldhelloworldhelloworldhellow
orldhelloworldhelloworl REG_SZ

E:\ >

After removing the key from the registry with Reglyzer

E:\ reg query HKEY_LOCAL_MACHINE\SOFTWARE\empty
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\SOFTWARE\empty

E:\ >

Best of luck mike king

time(r) is a trademark of Universe(c)
Public use permited by fair use agreement ( copyright [NULL] )
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.4

wkYEARECAAYFAkMNSykACgkQUjm7xSZSd8FxBgCgkxvav4tmXZY5te5K2hCNPmHekV4A
nRGuGi5KnT0tNLvLSIP7HSCFaQyi
=uvzy
-----END PGP SIGNATURE-----


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



-- 
ME2  <http://www.santeriasys.net/>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: