A days later the mail server stops working and the sysadmin turns up at my desk. Turns out the anti-virus scanner had been unzipping and scanning repeatedly. It eventually filled up the entire disk and bad things happened.
A days later the mail server stops working and the sysadmin turns up at my desk. Turns out the anti-virus scanner had been unzipping and scanning repeatedly. It eventually filled up the entire disk and bad things happened.
The school IT manager (who, incidentally, apart from this once I was always on good terms with) was rather annoyed at me the next day, for the nightly backup had fallen over the previous night and he had found the problem. You see, what to me was H:\ was \\galaxy\users$\chrism, which on that server was D:\users\chrism. So that 256-or-so character path became longer than 256 characters on the server and the backup software hadn't been written carefully enough to cope with what was a perfectly valid NTFS path, but not a valid path for the normal Win32 API function calls.
How was I to know it would do that?
[1] http://msdn.microsoft.com/en-us/library/windows/desktop/aa36...
[1] http://msdn.microsoft.com/en-us/library/windows/desktop/aa36...
EPS, an interpreted language, was designed to let financial analysts run economic projections. It contained various kinds of arrays.
One day, the systems programmers announced a new feature, first released to the test mainframe: a new structure, called containers IIRC, with the twist being that any cell in a container could itself consist of a container.
You know where this is going:
For I = 1 to 100
ContX[1] = ContX
EndFOR
10 seconds later, EPS on the test mainframe had crashed. Coincidence? Hmmmmmm.So far, my cover was my inquiring mind. But then I ran the loop again, with the same results.
A minute later, there was Massachusetts on the phone, in the person of my friend Kevin, lead EPS developer: "Hey, the answer is 47. What the hell are you doing?"
I was outraged. Basically, the IT manager preferred to use punishment as his means of security, rather than actually doing his job.
Tossing a brick through a window doesn't mean that the window should have been thicker.
There is nobody to blame for this, actually. Neither could the kid have known that this was bad (and the child-like curiosity is hardly something worth a punishment,) nor could the sysadmin really do anything to prevent it, except hang up a memo: please don't do that.
Though, in that case, you'd have some kids doing that over and over again out of a very different kind of curiosity.
It was "simple" way to hide files, by making their names very long indeed.
Rule: "You can have at most 50 sub-directories."
coder-action:
#define MAX_SUB_DIRECTORY_NUM 50
hacker-action: main(int argc, char *argv[]) {
int i;
for (i = 0; i < atoi(argv[1]); i++) {
create_subdir( ... );
}
}
Plus experiments.The difference is that the coder is just doing their job so they note the limitation and move on, the hacker is curious and trys to test to see if its a hard limit, a soft limit, a big problem, a little problem.
It's very confusing when you're not expecting it--you can dig into the folder and delete all the subdirectories of it that don't have overlong paths just fine, but there'll be one series of empty directories left over that just refuse to go away. Then you flatten them out from their nested configuration, and suddenly the problem goes away.
I can only imagine what would have happened. Can you share more details about that.
Also, wonder how the mail servers these days are equipped to handle such attachments. Can someone throw light on that? Is it just plain simple to detect these files?
Compression quines and bombs are a great way to screw up automated systems. Possessing or transmitting them can easily cause a denial of service.
From Wikipedia: A quine is a computer program which takes no input and produces a copy of its own source code as its only output. http://en.wikipedia.org/wiki/Quine_(computing)
Or are those scanners just rejecting files that are too large or deep?
Some malware is remarkably unsophisticated and relied on users installing it and giving it permissions to run.
I hope they're not silently rejecting files.
(The Grugq sells high value 0days and is a respected member of the hacking community) http://www.csoonline.com/article/216370/where-is-hacking-now...
I've worked with a leading commercial scanner that failed to respect the max depth parameter even when set. It would scan for days before we killed it.