some followup (from Microsoft), concerning the vulnerabilties in CCID driver/firmware, to
be considered. Interestingly, it concerns "unmanaged" access to the firmware's CCID, via PC/SC Direct, exactly as we were discussing.


Peter

--------------------


In order to send or receive an Escape command to a reader, the DWORD registry value EscapeCommandEnable must be added and set to a non-zero value under the HKLM\SYSTEM\CCS\Enum\USB\Vid*Pid*\*\Device Properties key.


Then the vendor IOCTL for the Escape command is defined as follows: #define IOCTL_CCID_ESCAPE SCARD_CTL_CODE(3500).


With the enabled Escape Command, security against malicious escape commands becomes the reader's responsibility.


Dan Griffin [MS]


_________________________________________________________________
MSN Toolbar provides one-click access to Hotmail from any Web page � FREE download! http://toolbar.msn.com/go/onm00200413ave/direct/01/


_______________________________________________
Muscle mailing list
[EMAIL PROTECTED]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to