Clan x86

Technical (Development, Security, etc.) => General Security Information => Topic started by: iago on March 08, 2006, 10:30:10 AM

Title: Critical vulnerability in ipconfig
Post by: iago on March 08, 2006, 10:30:10 AM
From a mailing list:

QuoteThis is a very serious matter. I've found an error in how the IPCONFIG
command handles incorrect command line input.

    C:\>ipconfig lksdflkjdsakfl

    Error: unrecongnized or incomplete command line.

Clearly the error line is supposed to say "unrecognized". I don't know if
this is an exploitable issue. I've only tested it on Windows XP SP2.

Let's hope Microsoft patches this before it's too late!! 

<edit> Apparently the German version of Microsoft Windows does not suffer from this problem.  You might consider setting your language to German until a patch comes out:
QuoteC:\>ipconfig lksdflkjdsakfl
Fehler: Unbekannte oder unvollständige Befehlszeile.



[disclaimer: this is a joke.  Anybody who thinks I'm serious should be shot.]
Title: Re: Critical vulnerability in ipconfig
Post by: Sidoh on March 08, 2006, 10:45:01 AM
Hahahah, that's great.
Title: Re: Critical vulnerability in ipconfig
Post by: Blaze on March 08, 2006, 11:50:05 AM
What the hell?  That guy is an idiot.
Title: Re: Critical vulnerability in ipconfig
Post by: iago on March 08, 2006, 11:55:58 AM
Quote from: Blaze on March 08, 2006, 11:50:05 AM
What the hell?  That guy is an idiot.
As I said, it's a joke :P
Title: Re: Critical vulnerability in ipconfig
Post by: Sidoh on March 08, 2006, 01:25:46 PM
Quote from: Blaze on March 08, 2006, 11:50:05 AM
What the hell?  That guy is an idiot.

/me shoots Blaze.
Title: Re: Critical vulnerability in ipconfig
Post by: Blaze on March 08, 2006, 06:47:48 PM
I understood it as a joke.  That doesn't make the joke or the person who made it up any less idiotic.
Title: Re: Critical vulnerability in ipconfig
Post by: Sidoh on March 08, 2006, 07:01:43 PM
Quote from: Blaze on March 08, 2006, 06:47:48 PM
I understood it as a joke.  That doesn't make the joke or the person who made it up any less idiotic.

Why?  Because you fail to see the humor in it?  Your problem.
Title: Re: Critical vulnerability in ipconfig
Post by: Blaze on March 08, 2006, 07:12:19 PM
I find humor in it, it's just TOO stupid.
Title: Re: Critical vulnerability in ipconfig
Post by: Sidoh on March 08, 2006, 08:21:20 PM
Quote from: Blaze on March 08, 2006, 07:12:19 PM
I find humor in it, it's just TOO stupid.

It's a subjective statement.  Calling someone an idiot is too, but it's a much more personal issue...
Title: Re: Critical vulnerability in ipconfig
Post by: Joe on March 16, 2006, 11:21:31 PM
The only thing I see wrong is they referred to a command line argument as a command line itself. Is that it?
Title: Re: Critical vulnerability in ipconfig
Post by: Ergot on March 16, 2006, 11:27:16 PM
Crap I'm affected by it :(.
Title: Re: Critical vulnerability in ipconfig
Post by: iago on March 17, 2006, 09:27:25 AM
Quote from: Joe on March 16, 2006, 11:21:31 PM
The only thing I see wrong is they referred to a command line argument as a command line itself. Is that it?
No.  Look harder. 
Title: Re: Critical vulnerability in ipconfig
Post by: Joe on March 17, 2006, 09:55:19 AM
And they spelled unrecognized wrong?
Title: Re: Critical vulnerability in ipconfig
Post by: iago on March 17, 2006, 10:15:32 AM
There you go. 
Title: Re: Critical vulnerability in ipconfig
Post by: Joe on March 17, 2006, 08:40:18 PM
I still don't get it though. Mind explaining?
Title: Re: Critical vulnerability in ipconfig
Post by: Sidoh on March 17, 2006, 08:46:05 PM
Quote from: Joe on March 17, 2006, 08:40:18 PM
I still don't get it though. Mind explaining?

Quote from: iago on March 08, 2006, 10:30:10 AM
[disclaimer: this is a joke.  Anybody who thinks I'm serious should be shot.]

/me aims a 12-gauge at Joe.
Title: Re: Critical vulnerability in ipconfig
Post by: Joe on March 18, 2006, 07:32:01 PM
I meant explain why it's supposed to be funny. Go away.
Title: Re: Critical vulnerability in ipconfig
Post by: Warrior on March 18, 2006, 09:04:49 PM
Because it's so stupid..can't you relate?
Title: Re: Critical vulnerability in ipconfig
Post by: Joe on March 18, 2006, 11:23:34 PM
Ok. I get it now, but don't find it funny, and I'm not sure why this is considered a vuln. Whatever. =p
Title: Re: Critical vulnerability in ipconfig
Post by: Sidoh on March 19, 2006, 12:50:56 AM
Quote from: Joe on March 18, 2006, 11:23:34 PM
Ok. I get it now, but don't find it funny, and I'm not sure why this is considered a vuln. Whatever. =p

It's ... not considered a vunerability.  That's why it's funny.

From the proportion of people who needed explanation to understand the humor behind this, I think we'd need a lot more shotgun shells than we were planning for, iago.
Title: Re: Critical vulnerability in ipconfig
Post by: iago on March 19, 2006, 12:57:07 AM
I can't afford many shells.  Can you just get a Goldeneye magnum (or whatever they called it) and line them up single file? 
Title: Re: Critical vulnerability in ipconfig
Post by: Quik on March 19, 2006, 01:15:33 AM
Quote from: iago on March 19, 2006, 12:57:07 AM
I can't afford many shells.  Can you just get a Goldeneye magnum (or whatever they called it) and line them up single file? 

Golden Gun?
Title: Re: Critical vulnerability in ipconfig
Post by: Sidoh on March 19, 2006, 02:55:07 AM
Quote from: iago on March 19, 2006, 12:57:07 AM
I can't afford many shells.  Can you just get a Goldeneye magnum (or whatever they called it) and line them up single file? 

It's brilliant!
Title: Re: Critical vulnerability in ipconfig
Post by: iago on March 19, 2006, 10:23:43 AM
Quote from: Quik on March 19, 2006, 01:15:33 AM
Quote from: iago on March 19, 2006, 12:57:07 AM
I can't afford many shells.  Can you just get a Goldeneye magnum (or whatever they called it) and line them up single file? 

Golden Gun?

No, the magnum.  The one that shoots through people and hits people behind them. 
Title: Re: Critical vulnerability in ipconfig
Post by: Joe on March 19, 2006, 01:55:06 PM
Good idea. Wait, shit..