Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: Bug in Norton FireWall 2003

From: pr00f <pr00f(at)pr00f.org>
Date: Tue Aug 12 2003 - 03:38:23 EDT

Even a "hard-to-guess window title" wouldn't be enough. There are API functions to grab window information from any window currently under the mouse pointer. Throw such a query into a timer, and hover the mouse over the window you want to get the title of. Bingo.

  • pr00f

Michael Wojcik <Michael.Wojcik@microfocus.com> wrote



> From: Boy Bear [mailto:eyal067@walla.co.il]

Ah, machine translation.

A cursory glance through the VB source [see original message] suggests that
the proposed exploit is to have a trojan recognize the firewall pop-up asking if the trojan should be permitted network access, and spoofing the
user input to grant it. Simple enough.

There appears to be a bug in the included source:

> Private Sub wHideShow(HideShow As Boolean)

Presumably one of "SW_SHOW" should be "SW_HIDE". Since wHideShow is never
used by the program, and "HideShow" is not exactly a meaningful parameter
name, it's hard to guess which. Then again, since wHideShow is never used,
it doesn't really matter.

Do you need help?X

I suppose a simple defense for "personal firewall" vendors against this sort
of thing would be to use hard-to-guess window titles for their popups...

-- 
Michael Wojcik
Principal Software Systems Developer, Micro Focus


-- 
If one cannot enjoy reading a book over and over again, there is no use
in reading it at all.
                -- Oscar Wilde
Received on Tue Aug 12 12:00:55 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:07:41 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library