|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
[Full-disclosure] another filename bypass vulnerability - from cmd.exe
From: Aditya Deshmukh (aditya.deshmukh
online.gateway.strangled.net)
Date: Wed Nov 16 2005 - 06:18:34 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Was doing some testing [xfocus-AD-051115]
Ie Multiple antivirus failed to scan
malicous filename bypass vulnerability
The system is windows 2000 sp4 srp5 with
all other patches upto date.
At the command prompt cmd.exe execute
the following with the results.
I copy and paste from cmd.exe
-------------------------------------------------------------------
E:\TEMP>cd test
E:\TEMP\test>copy %windir%\system32\calc.exe
1 file(s) copied.
E:\TEMP\test>ren calc.exe calc.exe.zip
E:\TEMP\test>dir /b
calc.exe.zip
E:\TEMP\test>calc.exe.zip
E:\TEMP\test>
-------------------------------------------------------------------
This bring up the calc.exe on the screen.
________________________________________________________________________
Delivered using the Free Personal Edition of Mailtraq (www.mailtraq.com)
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]