Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

RE: Bug in Norton FireWall 2003

From: <nowak.a(at)pg.com>
Date: Mon Aug 11 2003 - 17:15:21 EDT

> I suppose a simple defense for "personal firewall" vendors against this sort

Hello,

This simple defense may not be enough, as there are ways to find out the names of all "child" windows belonging to specific process.

Regards,
Andrzej

                                                                
 Internet Mail Message                                          
 Received from host:      [205.206.231.26]                      
                                                                


From: Michael Wojcik  on 08/11/2003 07:24 PM GMT
                                                                                      
                  Michael Wojcik           To:   vuln-dev@securityfocus.com           
            Cc:    (bcc: Andrzej Nowak-A/PGI)          
                                   Subject:      RE: Bug in Norton FireWall 2003      
                                                                                      
             08/11/2003 03:24 PM                                                      
                                                                                      
                                                                                      

> From: Boy Bear [mailto:eyal067@walla.co.il]

Ah, machine translation.

A cursory glance through the VB source [see original message] suggests that the proposed exploit is to have a trojan recognize the firewall pop-up asking if the trojan should be permitted network access, and spoofing the user input to grant it. Simple enough.

Do you need help?X

There appears to be a bug in the included source:

> Private Sub wHideShow(HideShow As Boolean)

Presumably one of "SW_SHOW" should be "SW_HIDE". Since wHideShow is never used by the program, and "HideShow" is not exactly a meaningful parameter name, it's hard to guess which. Then again, since wHideShow is never used, it doesn't really matter.

I suppose a simple defense for "personal firewall" vendors against this sort of thing would be to use hard-to-guess window titles for their popups...

--
Michael Wojcik
Principal Software Systems Developer, Micro Focus
Received on Mon Aug 11 18:09:36 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:40 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library