Computing.Net > Forums > Security and Virus > MS hidden-code flaw

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Click here to start participating now! Also, check out the New User Guide.

MS hidden-code flaw

Reply to Message Icon

Name: IronMan
Date: September 1, 2005 at 00:34:32 Pacific
OS: XP Pro
CPU/Ram: P4 512MB
Comment:


Interesting reading. . .

Last week, the Internet Storm Center, a group of security professionals that track threats on the Net, flagged a flaw in how a common Microsoft Windows utility and several anti-spyware utilities detect system changes made by malicious software. By using long names for registry keys, spyware programs could, in a simple way, hide from such utilities yet still force the system to run the malicious program every time the compromised computer starts up.

Complete Story



Sponsored Link
Ads by Google

Response Number 1
Name: Bob (by BigBob)
Date: September 1, 2005 at 07:41:10 Pacific
Reply:

Very Interesting !!!

" You're only as safe as your last update Please Post Back To Let Us Know If We Helped"


0

Response Number 2
Name: anonproxy
Date: September 1, 2005 at 13:43:15 Pacific
Reply:

The real issue is what OS/software combination you are using.

The registry is fairly hacked. XP/2003 accepts a fixed key size of ~16,000 characters (Unicode or ASCII), while 2000 accepts ~16k (Unicode) or ~250 characters, and 9x/ME only handles 255 ANSI. Values are also handled differently, where 9x/ME have a cap, but XP/2003 have only the limit of memory. Values longer than 2k are stored as files in the registry.

Yet another complexity exists - the size of all values for a key cannot exceed 64K, but obviously the above rule breaks that. I'd like to know how those reconciled in the system.

Win32 may or may not handle all these differences transparently across platforms. It depends on how much refactoring was done (it's possible the mistake was in fact made then). The OS version is key to this, though.

Best case scenario, the Win32 API is fine and software vendors need to recompile with new conditions. Worst case Microsoft needs to refactor. Actually, both those are bad, because home users tend to lag in patching.



0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


YOWZA - An Addition to th... .CHM files troubleshoot



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: MS hidden-code flaw

Now MS Word has a security flaw www.computing.net/answers/security/now-ms-word-has-a-security-flaw/6329.html

Temporary Internet Files ? www.computing.net/answers/security/temporary-internet-files-/9883.html

More factors in online security www.computing.net/answers/security/more-factors-in-online-security/10758.html