Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 8th, 2011, 10:15 AM
Gullible Jones
 
Posts: n/a
Default Workaround for the shortcut loading vulnerability on Win2k?

Specifically this vulnerability: http://www.microsoft.com/technet/sec.../ms10-046.mspx

I'm trying to give away an old Pentium II era computer, and Win2k SP4 is the only Windows version that'll run properly on it. I figure someone could put it to good use for document processing or something. But I want it to be secure enough that you can stick in a USB stick without the possibility of instant infection.

The autorun.inf thing I can deal with. Problem is, the shortcut vulnerability is unpatched and unpatchable in Windows 2000. There is a registry hack to deal with it, but that just makes shortcut icons not load, which compromises the user's experience rather badly.

So I came up with another possibility... Use a third-party file manager. The most likely install vector for malware using this vulnerability would be Explorer, not the taskbar; I figure that, if the third party FM doesn't use too many Explorer DLLs, it won't have the vulnerability, and can be used with reasonable safety.

The big question is... How likely is it that alternative file managers will use the vulnerable Explorer DLLs (I think the main one is Shell32.dll)? Is there any way I can test for the vulnerability in a given file manager?
  #2  
Old March 8th, 2011, 11:33 AM
Rmus Rmus is offline
Exploit Analyst
 
Join Date: Mar 2005
Posts: 3,624
Default Re: Workaround for the shortcut loading vulnerability on Win2k?

I think there are just too many variables to try to "out-think" exploits as you are attempting to do.

When I finally retire my Win2K system, I'll junk it. I wouldn't chance giving it to someone who doesn't have security in place to run a non-supported, unpatched system.


----
rich
  #3  
Old March 8th, 2011, 04:41 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,849
Exclamation Re: Workaround for the shortcut loading vulnerability on Win2k?

Hi,

You could still use it with HMP as it protects against that vulnerability

Name:  hm1.gif
Views: 35
Size:  5.2 KB

Name:  hm2.gif
Views: 35
Size:  18.0 KB

http://www.surfright.nl/en/hitmanpro

PS - To those that might wonder, i know my version isn't the latest
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #4  
Old March 8th, 2011, 06:13 PM
Gullible Jones
 
Posts: n/a
Default Re: Workaround for the shortcut loading vulnerability on Win2k?

Oh... Didn't realize Hitman Pro could patch it on Win2k. Thanks.

(I ended up putting Zenwalk Linux on it. It's... Not very fast, but it's usable.)
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 03:08 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums