RE: [Full-disclosure] Microsoft Windows Vista/2003/XP/2000 file

看板Bugtraq作者時間19年前 (2007/03/10 02:04), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/3 (看更多)
So, let me get this. An app storing sensitive data doesn't make its own temp storage folders in a secure location, and instead relies upon one of the few folders in Windows that all users have Full Control to, and this is a Windows problem? In Linux, if an app uses \tmp, is that a Linux issue? Sounds like a developer issue to me. Roger -----Original Message----- From: Tim [mailto:tim-security@sentinelchicken.org]=20 Sent: Friday, March 09, 2007 11:20 AM To: Roger A. Grimes Cc: bugtraq@securityfocus.com; full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Microsoft Windows Vista/2003/XP/2000 file management security issues I find your assessment somewhat short-sighted. I have conducted code reviews on several commercial apps which use C:\TEMP in very insecure ways to store sensitive data. It seems some of these attacks would be possible in those situations. Sure, Windows is already pathetically insecure against an attackers already on the local system, but this would be yet another attack vector. tim
文章代碼(AID): #15yQ6r00 (Bugtraq)
文章代碼(AID): #15yQ6r00 (Bugtraq)