4 ms·
What is interesting here is that a signed piece of software can pick up an unsigned dll, execute it, and that execution causes a compromise of the system.
by WirelessGigabit 2y ago
What is interesting here is that a signed piece of software can pick up an unsigned dll, execute it, and that execution causes a compromise of the system.
- speps 2y agoRaymond Chen has a ton of "being on the other side of the airtight hatchway" articles. Most relevant I found: https://devblogs.microsoft.com/oldnewthing/20200420-00/?p=103685 https://devblogs.microsoft.com/oldnewthing/20200420-00/?p=10... Probably in this case the installation of the crack requires admin privileges to modify files in "Program Files" folder. Boom, you've broken the rules ;)
- saagarjha 2y agoTurns out that building the airtight hatchway halfway through the crew’s sleeping quarters was a bad decision.
- Nextgrid 2y agoThis also raises a vulnerability. The author seems convinced this pirated copy is safe because the main binary is signed by Ableton, but there’s no guarantee if there’s a signature check on any of its dependent files (or that the check is not vulnerable or the parsing isn't vulnerable in some way which would allow hijacking the execution flow).
- mhh__ 2y agoShared libraries are a scam