Archive for September of 2005

I'm gonna scthream and scthream until I'm sthick!

September 23, 2005
Apparently, exploit finding and exploiting security holes on Firefox is mainly done by people prone to temper tantrums if they don't get the attention they think they deserve.
“Exploit author SkyLined credits several people with assisting him in the creation of PwnZilla 5. In his description of the code, he says, "Since Netscape has not replied to reports about this vulnerability I've chosen to release it."”

[...]

“The vulnerability was originally reported to the Mozilla Foundation by Tom Ferris, who elected to make it public before fixed versions of Firefox and the Mozilla Application Suite were released. SecurityProNews reporter John Stith interviewed Tom Ferris about the IDN vulnerability last week, providing more insight into why Ferris chose to publish details of the flaw. Stith's article states: "He [Ferris] also commented that when he initially submitted all his information to Mozilla, they seemed at odds and he felt put out by them... Microsoft has always 'treated him more like a professional.' He said he felt the folks over at Mozilla treated him more like a kid."”

PwnZilla 5 Exploits IDN Link Buffer Overflow - MozillaZine Talkback

Share and Enjoy 2: Electric Boogloo

September 19, 2005
Regarding an older post, I finally managed to solve both problems. In case anyone else runs into them:

The Samba Problem: ports! The following ports need to be opened on the Linux box for trouble-free sharing with Windows:
  • 137:udp (AKA netbios-ns)
  • 138:udp (AKA netbios-dgm)
  • 139:tcp (AKA netbios-ssn)
  • 445:tcp (AKA microsoft-ds)

The Sharing Tab Problem: registry! As per an answer the the ExpertSexChange site (which you can't read unless you pony up some cash), my registry had been edited to disable it (probably by one of those tweak registry programs I sometimes foolishly play with). To repair I had to recreate the following entry:
[HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\Sharing]
“(default)”="{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}“

and edit another to move the value in the ”~~disabled~~“ key back into ”(default)“:
[HKEY_CLASSES_ROOT\CLSID\
 {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}\InProcServer32]
”(Default)"="ntshrui.dll“
”~~Disabled~~"="ntshrui.dll“
”ThreadingModel"="Apartment"