Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: antiRepublicrat; stripes1776

This is a MAJOR flaw. I mean, it’s below OS level error, it’s systemic. Every program calls and looks for dll’s. And it seems their is no “special” place for them, you can look on your desktop!

WOW!

So much for the late great Windows 7....


15 posted on 08/24/2010 2:06:05 PM PDT by RachelFaith (2010 is going to be a 100 seat Tsunami - Unless the GOP Senate ruins it all...)
[ Post Reply | Private Reply | To 13 | View Replies ]


To: RachelFaith
This is a MAJOR flaw. I mean, it’s below OS level error, it’s systemic. Every program calls and looks for dll’s.

Yes, this is a major security hole. It will keep network administrators very busy locking down their networks.

Unfortunately, the every day home user is not a network or system administrator. An operating system should not even allow this sort of behavior.

16 posted on 08/24/2010 2:18:07 PM PDT by stripes1776
[ Post Reply | Private Reply | To 15 | View Replies ]

To: RachelFaith

There’s a special place for them, System32. It also looks in the same folder the exe was run from, which could be the desktop. This has been how Windows works since day 1, somebody just finally figured out you could stick evil dlls in the search path.


20 posted on 08/24/2010 3:01:57 PM PDT by discostu (Keyser Soze lives)
[ Post Reply | Private Reply | To 15 | View Replies ]

To: RachelFaith
I mean, it’s below OS level error, it’s systemic.

It's systemic, but I wouldn't call it below OS level.

Every program calls and looks for dll’s.

Mine don't specifically look for any DLLs, so wouldn't be subject to this flaw. I compile everything into the executable. I avoid P/Invoke like the plague. Of course my programs aren't quite as big as the vulnerable ones mentioned. They could indirectly call DLLs by invoking C# methods that cause the runtime to invoke DLLs, but those would be called within the .NET system to known locations. You'd need a broke .NET installation to make it vulnerable, and then that might cause the program to not run in the first place.

Yes, I am a Windows developer, and my favorite language is C#.

30 posted on 08/24/2010 5:58:09 PM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 15 | View Replies ]

To: RachelFaith
Every program calls and looks for dll’s.

Can I persuade you to make a sizeable monetary wager on that?

45 posted on 08/25/2010 5:14:11 AM PDT by tacticalogic
[ Post Reply | Private Reply | To 15 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson