Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: How to.... |
|---|---|
| Date: | Wed, 28 Sep 2005 10:18:18 +0100 |
On Tue, 2005-09-27 at 11:32 +1000, Greg wrote:
....really shoot your XP machine in the foot, so to speak. Pick any program shortcut that is pinned to your start menu. If you don't have any, find any old program shortcut (or make one) then pin it to your start menu. Now go find some other shortcut to a completely different program and open it's properties. Copy the full path info from that one and past it into the path info in the properties for that other shortcut that is pinned to the start menu and click OK to make it stick. Now carefully look at that icon. It hasn't changed. Now click on it. The icon now starts that other program instead of the one it looks like it is SUPPOSED to start. Now while all that is simple "so what?" to most of you, think of this - I deal in a lot of low level security stuff that is below the radar of a lot of you but if an icon that is frequently used in the list of commonly used programs or those pinned to the start menu can be so easily changed to start some other program yet not look like it was tampered with at all, why couldn't the next Trojan include code to do this? Eg, place a Trojan on the C drive, copy the full path info into the "Windows Update" icon on your start menu (for example) where it runs that Trojan instead. That Trojan may do what it is designed to do and also do the actual starting of Windows Update after that.
When malware has this sort of access the game is already over, whatever the user can do the malware can do, or are you advocating that the user not be allowed to choose the icons on their shortcuts?
What stops a local user or a Trojan doing this in a normal XP installation that hasn't been changed and all runs at admin levels as so many businesses do?
Nothing, it is there start menu. However they can't modify anything that affects the start menu of other users because they by default don't have permissions (NTFS) to do so. No privilege escalation is happening here, the user is just modifying their own environment. -- With Regards.. Barrie Dempster (zeedo) - Fortiter et Strenue "He who hingeth aboot, geteth hee-haw" Victor - Still Game blog: http://reboot-robot.net sites: http://www.bsrf.org.uk - http://www.security-forums.com ca: https://www.cacert.org/index.php?id=3
smime.p7s
Description: S/MIME cryptographic signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: New Job., Que |
|---|---|
| Next by Date: | Re: Checkpoint Fw1 syslog logging. Any solution ?, Chris Clymer |
| Previous by Thread: | Re: How to...., Greg |
| Next by Thread: | RE: How to...., Clarkson, Dustin |
| Indexes: | [Date] [Thread] [Top] [All Lists] |