HM Software S to Infinity 3.0 – Multiple Vulnerabilities
漏洞ID | 1053449 | 漏洞类型 | |
发布时间 | 2000-06-15 | 更新时间 | 2000-06-15 |
CVE编号 | N/A |
CNNVD-ID | N/A |
漏洞平台 | Windows | CVSS评分 | N/A |
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/1368/info
A number of vulnerabilities exist in HM Software S to Infinity, a security access control, desktop lockdown and transparent encryption application. Intended features include restriction of access to folders, files, floppy and CD-ROM drives, etc.
Early versions of S to Infinity allows the capability of any user to rename files and directories which opens up the possibility of a number of exploits:
- Renaming the S to Infinity directories in /Program Files and /Winnt/System will cause the program to cease to function.
- S to Infinity implicitly trusts any allowed program on the system. However, it can be configured to set *.exe to read-only. Therefore, a user can run any application by copying the executable program to something.txt and then renaming that copy to a trusted executable like notepad.exe.
Other security flaws present in S to Infinity:
- The drive invisibility mechanism can be bypassed by using Find, Internet Explorer, or Open and Save Dialogue boxes. Searching for the hidden drive letter and a known file in Find will allow access to files on the hidden drive. A user can open a hidden drive in Internet Explorer by clicking on a link that refers to the particular drive (eg. <a href="c:">Link</a>).
- File and directory attributes can be modified using the DOS attrib command. StoI file-level protection does not rely on DOS file attributes, so this will not affect StoI settings.
https://github.com/offensive-security/exploit-database-bin-sploits/raw/master/bin-sploits/20022.exe
相关推荐: SGI IRIX System Manager sysmgr GUI漏洞
SGI IRIX System Manager sysmgr GUI漏洞 漏洞ID 1207382 漏洞类型 未知 发布时间 1998-04-02 更新时间 1998-04-02 CVE编号 CVE-1999-1183 CNNVD-ID CNNVD-19980…
© 版权声明
文章版权归作者所有,未经允许请勿转载。
THE END
喜欢就支持一下吧
恐龙抗狼扛1年前0
kankan啊啊啊啊3年前0
66666666666666