4 ms·
NTFS has supported them for ages. The main issue is that they're locked behind elevated permissions or having developer mode enabled (as of Windows 10.) My und
by Pathogen-David 4y ago
NTFS has supported them for ages. The main issue is that they're locked behind elevated permissions or having developer mode enabled (as of Windows 10.)
My understanding is Microsoft's concern is that applications and OS components not expecting them could lead to security issues. Not sure how real that concern is, but that's the excuse I've heard.
- nemothekid 4y ago>Not sure how real that concern is, but that's the excuse I've heard. Bufferoverun I guess? I haven't programmed Windows in years, but there's plenty of code I've seen that is pretty much char path[MAX_PATH]; res = some_func(&path); from there you put in a large path and then you get your RCE.
- MereInterest 4y agoThat would be for removing the 260 character limit, not for enabling of symlinks.
- MereInterest 4y agoI've looked before, and have never found a definitive answer from Microsoft. I've heard some speculation that it the nebulous security issues would be from a program that checks the permissions of a symlink's target, then opens the symlink. An attacker could then modify the symlink after the permission check but before the file is opened, escalating access by pointing to a restricted file.
- pxc 4y agoIt's a kind of attack called a symlink race, which is also possible on other operating systems. There are kernel parameters for hardening against symlink races on Linux, and they just disable symlinking into world-writable locations. I'm not sure why Windows can't use a less invasive mitigation like that, but I guess there must be one.
- int_19h 4y agoA lot more tends to be world-writable in Windows, for starters.