Nmap Development mailing list archives

Re: nmap potentially vulnerable to Windows DLL Hijacking


From: Nikhil Mittal <nikhil_uitrgpv () yahoo co in>
Date: Sun, 5 Sep 2010 18:52:54 +0530 (IST)


    I surely will test nmap latest build and later the other programs.

    >>You can write what you like, but there is no vulnerability here
    I disagree. Exploitability is very less but you cannot discard the vulnerability altogether.

    >>it might have become vulnerable if such associations were added in the future.
    That is exactly my point.

    Thanks for fixing it because I really love nmap. Keep up the good work.

    Regards,
    Nikhil Mittal


    --- On Sun, 5/9/10, David Fifield <david () bamsoftware com> wrote:


        From: David Fifield <david () bamsoftware com>
        Subject: Re: nmap potentially vulnerable to Windows DLL Hijacking
        To: "Nikhil Mittal" <nikhil_uitrgpv () yahoo co in>
        Cc: nmap-dev () insecure org
        Date: Sunday, 5 September, 2010, 7:58 AM

        On Sat, Sep 04, 2010 at 08:35:57PM +0530, Nikhil Mittal wrote:
        > I cannot find where to download the latest commit. Do I need rights to check
        > out nmap SVN??

        Follow the instructions at http://nmap.org/book/install.html#inst-svn.
        svn co --username guest --password "" svn://svn.insecure.org/nmap

        > Also, request your consent to publish it on Bugtraq/Full Disclosure.

        You can write what you like, but there is no vulnerability here, at
        least as far as I understand DLL hijacking. Even though Nmap loads
        airpcap.dll with an insufficiently qualified path (through WinPcap), its
        lack of file name extension associations means that an attacker doesn't
        have a way to get control over the current directory.

        I do thank you for bringing this to our attention. Even though Nmap does
        not make file name extension associations now, it might have become
        vulnerable if such associations were added in the future.

        Also keep in mind that I have only personally checked nmap.exe and
        zenmap.exe so far. I would appreciate help testing the other programs,
        and independent confirmation of what I have already tested.

        David Fifield



_______________________________________________
Sent through the nmap-dev mailing list
http://cgi.insecure.org/mailman/listinfo/nmap-dev
Archived at http://seclists.org/nmap-dev/


Current thread: