View Single Post
Old 07-09-2005   #1 (permalink)
Malware startup may hide in your registry

A researcher named Igor Franchuk has discovered a weakness in Microsoft Windows, which can be exploited to hide certain information.

The weakness is caused due to an error in the Registry Editor Utility (regedit.exe) when handling long string names. This can be exploited to hide strings in a registry key by creating a string with a long name, which causes this string and any subsequently created strings in the key to be hidden.

Successful exploitation e.g. makes it possible for malware to hide strings in the "Run" registry key. However, these hidden strings created after the string with the overly long name will still be executed when the user logs in.


http://secunia.com/advisories/16560/
Dai_Nasty
Adminestrone
 
Dai_Nasty's Avatar
 
Join Date: Oct 2003
Location: Lincoln UK
Age: 60
Posts: 3,471
Thanks: 4
Thanked 7 Times in 6 Posts
Dai_Nasty has disabled reputation
Send a message via MSN to Dai_Nasty

-=| David |=-

We're not going away anytime soon...




Reply With Quote Dai_Nasty is offline