Le Lundi 23 Octobre 2006 18:07, Tillmann Werner a écrit : > Luis, > > > Tried it on Win2k3 SP1: > > C:\Documents and Settings\Administrator>%COMSPEC% /K > > "dir\\?\AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA > > AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA > >AA A AAAA > > AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA > >AA A AAAA > > AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA" > > System replied: > > The filename or extension is too long. > > > > > > YEah! Buffer Overflow Windows XP SP2 > > > > I Hill debug this. > > What makes you think there is a buffer overflow? I'd say the 'dir' command > reports an error for parameters beyond 256 chars. Just plain error > handling, not a security issue, or am I missing something?
/me agrees Tillmann More info there : http://support.microsoft.com/default.aspx?scid=kb;en-us;177665 -- Cordialement, Arnaud Jacques Consultant Sécurité Securiteinfo.com La Sécurité Informatique - La Sécurité des Informations. http://www.securiteinfo.com _______________________________ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/