OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Full-disclosure] DLL hijacking with Autorun on a USB drive

From: Atul Agarwal (atulsecfence.com)
Date: Thu Aug 26 2010 - 15:12:44 CDT


IMHO, I think its rather useless.

Instead of it executing "wab.exe (Windows Address Book) and open the file
test.vcf", one can directly get any .exe file open.

If one
Thanks,
Atul Agarwal
Secfence Technologies
www.secfence.com

On Fri, Aug 27, 2010 at 1:23 AM, matt <mattattackvector.org> wrote:

> Hey guys..
>
> Here's an example the DLL hijacking attack using a USB drive with autorun.
> I haven't seen this done yet, so I figured I'd post it.
>
> http://www.attackvector.org/autorun-dll-hijacker-usb-stick/
>
> - matt
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/