Re: Windows Vista winsat.exe Integer Overflow
[email protected] Sun, 30 Mar 2008 23:52:25 -0400
| Newsgroups | gmane.comp.security.vulnerabilities |
|---|---|
| Message-ID | <[email protected]> |
--==_Exmh_1206935545_4169P Content-Type: text/plain; charset=us-ascii On Fri, 28 Mar 2008 23:03:55 EDT, Steve Shockley said: > You'd still have to convince the user to bypass UAC when he wasn't > expecting a UAC prompt, in addition to getting them to run it in the > first place. Experience has proved that neither of these should be all that difficult for an attacker - an incredibly large percentage of users will go ahead and run a .exe, clicking through multiple security warnings, if it promises to do something interesting (usually having to do with somebody famous wearing too little clothing while misbehaving...) --==_Exmh_1206935545_4169P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFH8F/5cC3lWbTT17ARAs7dAKDuhDZgkAm/LFAvMKyoUDwRL5XNvQCdFwRl IYUuZkbLw4yFS7vUx8UbXRY= =8dme -----END PGP SIGNATURE----- --==_Exmh_1206935545_4169P--