<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DLL-load Hijacking Vulnerability and MS09-014/MS09-015</title>
	<atom:link href="http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Thu, 29 Apr 2010 13:25:27 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
		<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-968</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Tue, 26 May 2009 22:42:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-968</guid>
		<description>wow, thanks!</description>
		<content:encoded><![CDATA[<p>wow, thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-966</link>
		<dc:creator>Richard</dc:creator>
		<pubDate>Tue, 26 May 2009 15:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-966</guid>
		<description>Everytime i come back here I&#039;m reminded why I added your site to my favourites:)</description>
		<content:encoded><![CDATA[<p>Everytime i come back here I&#8217;m reminded why I added your site to my favourites:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-959</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Mon, 18 May 2009 17:00:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-959</guid>
		<description>Windows 2000 not vulnerable.
Windows XP, 2003, Vista and 2008 (core installation too) are vulnerable.. Both 32-bit and 64-bit versions of each one.
Regarding Windows 7.. I really don&#039;t know.. Haven&#039;t test it.

See: http://www.microsoft.com/technet/security/bulletin/ms09-015.mspx#E5C</description>
		<content:encoded><![CDATA[<p>Windows 2000 not vulnerable.<br />
Windows XP, 2003, Vista and 2008 (core installation too) are vulnerable.. Both 32-bit and 64-bit versions of each one.<br />
Regarding Windows 7.. I really don&#8217;t know.. Haven&#8217;t test it.</p>
<p>See: <a href="http://www.microsoft.com/technet/security/bulletin/ms09-015.mspx#E5C" rel="nofollow">http://www.microsoft.com/technet/security/bulletin/ms09-015.mspx#E5C</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yuv</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-958</link>
		<dc:creator>yuv</dc:creator>
		<pubDate>Mon, 18 May 2009 07:44:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-958</guid>
		<description>What Windows versions are vulnerable for this kind of attack ?</description>
		<content:encoded><![CDATA[<p>What Windows versions are vulnerable for this kind of attack ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-954</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Thu, 14 May 2009 01:23:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-954</guid>
		<description>Once triggering the DLL-load hijacking vulnerability on an application, the hijacked DLL will run in this application privilege. And by that allowing privilege escalation.</description>
		<content:encoded><![CDATA[<p>Once triggering the DLL-load hijacking vulnerability on an application, the hijacked DLL will run in this application privilege. And by that allowing privilege escalation.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Qube</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-953</link>
		<dc:creator>Qube</dc:creator>
		<pubDate>Thu, 14 May 2009 00:23:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-953</guid>
		<description>great post :D

but this makes me wonder, why did Microsoft issued MS09-015 as a elevation of privilege vulnerability?

&quot;Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)&quot;</description>
		<content:encoded><![CDATA[<p>great post :D</p>
<p>but this makes me wonder, why did Microsoft issued MS09-015 as a elevation of privilege vulnerability?</p>
<p>&#8220;Blended Threat Vulnerability in SearchPath Could Allow Elevation of Privilege (959426)&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-952</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Wed, 13 May 2009 23:49:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-952</guid>
		<description>@anon - not necessarily. 
I&#039;ve mentioned it in the post, like you, at first Microsoft also gave that argument - to place a file on the user&#039;s desktop, it have to be owned.
But, using the Safari Carpet Bomb vulnerability or other methods as I suggested in the post ending, it is possible to place DLL files on user&#039;s boxes without owning them.</description>
		<content:encoded><![CDATA[<p>@anon &#8211; not necessarily.<br />
I&#8217;ve mentioned it in the post, like you, at first Microsoft also gave that argument &#8211; to place a file on the user&#8217;s desktop, it have to be owned.<br />
But, using the Safari Carpet Bomb vulnerability or other methods as I suggested in the post ending, it is possible to place DLL files on user&#8217;s boxes without owning them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anon</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-951</link>
		<dc:creator>anon</dc:creator>
		<pubDate>Wed, 13 May 2009 23:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-951</guid>
		<description>if an attacker can &quot;place&quot; a file on the users desktop, doesn&#039;t he already own the box?

enlighten me</description>
		<content:encoded><![CDATA[<p>if an attacker can &#8220;place&#8221; a file on the users desktop, doesn&#8217;t he already own the box?</p>
<p>enlighten me</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NadavN</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-950</link>
		<dc:creator>NadavN</dc:creator>
		<pubDate>Wed, 13 May 2009 20:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-950</guid>
		<description>Interesting.

I liked the demonstrations. It appears Microsoft just infinitely chasing its own tail.</description>
		<content:encoded><![CDATA[<p>Interesting.</p>
<p>I liked the demonstrations. It appears Microsoft just infinitely chasing its own tail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Trancer</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-949</link>
		<dc:creator>Trancer</dc:creator>
		<pubDate>Wed, 13 May 2009 10:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-949</guid>
		<description>It&#039;s not new that Microsoft isn&#039;t honest regarding their security patches and bulletins.
Each Microsoft patch is chance to fix some undisclosed vulnerabilities, in addition to the vulnerabilities stated in the security bulletin. This is widely known as &quot;silent fixes&quot;.</description>
		<content:encoded><![CDATA[<p>It&#8217;s not new that Microsoft isn&#8217;t honest regarding their security patches and bulletins.<br />
Each Microsoft patch is chance to fix some undisclosed vulnerabilities, in addition to the vulnerabilities stated in the security bulletin. This is widely known as &#8220;silent fixes&#8221;.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John</title>
		<link>http://www.rec-sec.com/2009/05/12/dll-hijacking-vulnerability/comment-page-1/#comment-948</link>
		<dc:creator>John</dc:creator>
		<pubDate>Tue, 12 May 2009 19:18:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.rec-sec.com/?p=416#comment-948</guid>
		<description>Great post! 
you&#039;ve got some serious accusations here, but since you have your findings to support them, I believe that this post deserves a massive exposure.</description>
		<content:encoded><![CDATA[<p>Great post!<br />
you&#8217;ve got some serious accusations here, but since you have your findings to support them, I believe that this post deserves a massive exposure.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
