TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Full details on CVE-2015-0096 and the failed MS10-046 Stuxnet fix

82 pointsby mikeboabout 10 years ago

5 comments

cm2187about 10 years ago
Out of curiosity, does anyone understand why it was a good idea in the first place to have icons pointing to a DLL instead of having a static icon name or icon id?
评论 #9184340 未加载
orkjabout 10 years ago
This reminds me of how &quot;hacking a computer&quot; is depicted in a movie or in tv-series.<p>&quot;All we need to do is attach this usb stick and we can download all the files from their computer&quot;<p>Well, almost, at least.
upofadownabout 10 years ago
So Windows can run code simply by browsing to a directory with the default shell?<p>I have no words...
评论 #9183801 未加载
评论 #9184252 未加载
评论 #9184903 未加载
gpvosabout 10 years ago
I am assuming that the code being run is the DllMain which is normally called during LoadLibrary. The proper fix would have been to just map the DLL into memory <i>without</i> running DllMain, since that is not necessary to read the icons.
SirHoboabout 10 years ago
Its still so surprising to me that human error is still occurring in security. Surely, companies&#x2F;organisations should provide training to stop them form being insecure.
评论 #9184800 未加载