PDA

View Full Version : Is This True?



monkfi5h
11-07-2003, 05:18 PM
http://www.zeropaid.com/news/articles/auto/10022003i.php

Is this site true?


Malicious code
There exists malicious code in ES5.exe's "Search Service" packet handler. By sending packet 0Ch, sub-function 07h to the "Search Service"'s IP:Port, a remote attacker could delete any file the user is sharing. If the remote attacker uses "filenames" with a relative path in them (eg. "......WINDOWSNOTEPAD.EXE"), the remote attacker could also delete files in eg. the windows and windowssystem32 folders, or any other folder on the same partition as any of the shared folders. Since most users using Windows are in the Administrators group, a remote attacker could also delete the C:BOOT.INI file which is a required boot file used by ntldr.

IMPORTANT: This is not a bug! They intentionally added this code to ES5

ZaZu
11-07-2003, 05:36 PM
aparently so (http://www.klboard.ath.cx/index.php?showtopic=71360) :huh:

zapjb
11-08-2003, 06:39 PM
YES! http://www.klboard.ath.cx/index.php?showtopic=71360

Gre1
11-08-2003, 07:11 PM
I can't believe u didn't see that bright red topic and it says the exact same thing u just said.

.hack
11-08-2003, 07:14 PM
yup :ph34r:

.hack
11-08-2003, 07:15 PM
hahahahahahhaaha stfu

chinook_apache
11-08-2003, 07:18 PM
i had downloaded that es5 time ago but it was kinda shite it would download superfast about 15 meg then just idle...its shit wouldnt advise anyone to get it...so it had a malicious code then?...

random nut
11-08-2003, 07:48 PM
Who deleted my reply?

RealitY
11-09-2003, 01:51 AM
Originally posted by random nut@8 November 2003 - 11:48
Who deleted my reply?
Me...
:lol: :lol:

random nut
11-09-2003, 05:46 AM
Originally posted by REALITY+9 November 2003 - 03:51--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (REALITY &#064; 9 November 2003 - 03:51)</td></tr><tr><td id='QUOTE'><!--QuoteBegin-random nut@8 November 2003 - 11:48
Who deleted my reply?
Me...
:lol: :lol:[/b][/quote]
I knew you were SharePro, ShitHead. :D

RealitY
11-09-2003, 05:52 AM
Originally posted by random nut+8 November 2003 - 21:46--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (random nut @ 8 November 2003 - 21:46)</td></tr><tr><td id='QUOTE'>
Originally posted by REALITY@9 November 2003 - 03:51
<!--QuoteBegin-random nut@8 November 2003 - 11:48
Who deleted my reply?
Me...
:lol: :lol:
I knew you were SharePro, ShitHead. :D [/b][/quote]
SharePro deleted your post??
Oh fk hes a mod here too...