New XP SP1 and SP2 Exploit Found: Users can drag and drop into Startup Folder

Home -> Windows

12912 views

From the computer of: davak (390 recipes)
Created: Aug 19, 2004


Add a comment

Add to:
Add to stumbleuponAdd to del.icio.usDigg itAdd to FURL

SP2 has not fixed all of window's security problems. Users can still be tricked into dragging files into the startup area. IE 5.0, IE 6.0, and IE 6.1 systems are affected.

This works on SP1 and SP2 systems indeed. You can't expect one little 150 MB patch to fix all of microsoft's security problems, can you? :)

Here's the proof of concept site:
http://www.malware.com/wottapoop.html

I love proof of concept sites like this! When somebody says that XP has a certain blah, blah exploit, I listen and wait for the patch. However, when somebody proves to me that they can use it to drop a file onto my computer, that's when I get all pissed at Microsoft again.

No fix is available yet.

Source: http://secunia.com/advisories/12321/

Subscribe to the Tech-Recipes Newsletter

You can get tips like this delivered in your email every week!

Enter your Email

We will never, ever sell your email address or spam you.





Related recipes:

  Drag and Drop For Quick Outlook Tasks
  Vista: Add Shortcuts to Favorite Links Sidebar in Explorer
  Stop Programs Running At Start Up
  XP: Drag and Drop to Create a Shortcut in the Start Menu
  Winamp Skin Exploit Easily Installs Spyware, Trojans, or Worms
  Vista: Add to SendTo Menu
  XP: How to add to the Send To Menu in Windows
  Bloodhound.Exploit.6 False Positive found by Antivirus in Forums and Hijack Logs
  Never Click ANYTHING In A Spam E-mail (Scroll-bar Exploit Description)
  XP: Change Windows Automatic Update Settings

 

Sponsored links

 

Login

Nickname

Password

Don't have an account yet? You can create one. As a registered user you have some advantages like theme manager, comments configuration and post comments with your name.