ENdless Shortcut Loop Repeatedly Crashes Explorer. Security Issue?

G

Guest

Let's try this in the right section this time... :D

Hi there,
I was playing around with shortcuts today and I found what appears to be a
potentially malicious bug in Windows XP. It seems when two (modified)
Shortcuts (.LNKs) are pointing to each other, when Windows attempts to assign
one an icon Explorer closes and restarts. If the shortcuts are placed on the
Desktop then when Explorer restarts, the bug is triggered again, starting the
whole process over again. This also occurs after a reboot and when in Safe
Mode. My main concern is that if a user with malicious intent used this to
harm an incompetant user, the victim would most likely not be able to resolve
the problem. The looping can be ended by either killing Explorer.exe or by
deleting one of the shortcuts in the chain (both quite difficult when
Explorer is restarting every second or 2). I have created a PoC which will
work on the current user's Desktop. Just ask for a copy if you'd like to try
it.

Thanks,
Andy Bearman
 
A

Ayush

Replied To {REPLY BELOW}:
-------------------------------------------------------------

| Let's try this in the right section this time... :D
|
| Hi there,
| I was playing around with shortcuts today and I found what appears to be
a
| potentially malicious bug in Windows XP. It seems when two (modified)
| Shortcuts (.LNKs) are pointing to each other, when Windows attempts to
assign
| one an icon Explorer closes and restarts.

Windows warns if you try to point one shortcut to another shortcut so it
is not even possible.


| I have created a PoC which will
| work on the current user's Desktop. Just ask for a copy if you'd like to
try
| it.

You can simply delete one shortcut by running command prompt if this type
of thing ever happens.


--
Ayush [ Be ''?'' Happy ]

For any query, search - www.Google.com
Want to know about a term - http://en.wikipedia.org
Snip your long urls - http://snipurl.com/
 
G

Guest

okay firstly I did mention that the shortcut had been modified, in notepad to
be specific, and secondly my point was that if standard old-lady-type users
(sorry for stereotype) fell victim to this then it could piss a lot of people
off.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top