Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Microsoft Support > Windows XP Support
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

Windows XP Support Find support for Windows XP here.

Reply
 
Thread Tools
Old 07-18-2005, 03:46 PM   #1 (permalink)
Member
 
Join Date: Aug 2004
Posts: 24
OS: Win2K, XP Pro, XP Home, Suse Linux


How do they do that?

In the current issue of PC Magazine they review anti-spyware tools that prevent websites from changing your registry, installing keyloggers, or changing your Favorites.

I'm a software engineer and I don't understand how a website could do those things in the first place! Wouldn't it take executable code that could access the appropriate API's? If the browser is running with ActiveX and Java disabled how do websites manage, say, to access your Registry in order to change it?
plnelson is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-18-2005, 05:19 PM   #2 (permalink)
Tech, Microsoft Support
 
BMR777's Avatar
 
Join Date: Apr 2005
Location: Chicago, IL
Posts: 1,395
OS: XP Pro, XP Home, Vista Home Basic, Ubuntu Studio


Blog Entries: 2
VIA Security Holes?

BMR777
__________________
Brandon Rusnak

Protection: AVG Free Anti Virus :: Windows Defender :: Hosts File :: SiteAdvisor :: ZoneAlarm
Quick Fixes: 5 Steps to remove spyware
BMR777 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-18-2005, 05:31 PM   #3 (permalink)
Moderator Hardware Forum
 
Terrister's Avatar
 
Join Date: Apr 2005
Location: West Georgia, USA
Posts: 6,919
OS: Xp


Send a message via AIM to Terrister Send a message via MSN to Terrister
All the more reason to load all the updates from Microsoft. They plug these holes as they are found.
__________________
Terrister is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Old 07-18-2005, 05:44 PM   #4 (permalink)
Moderator
 
Join Date: Jan 2005
Location: San Diego
Posts: 2,127
OS: Vista SP1

My System

The most common method of executing your own code on their computer is by using buffer overruns. What you do is take advantage of code which doesn't check when too much data is loaded into a buffer. C doesn't range check for you. You have to do it yourself and lots of people forget. Since the data for the buffer is stored on the stack, all you have to do is load too much data into the buffer to overwrite a return address. You can arrange for the return address to aim at code which you have loaded into a string somewhere in memory. When the routine returns it goes to the return address which you set up. It starts executing your code and with all the privileges of whatever routine was running. This takes careful formatting of your data but that's no big deal if you're good with a disassembler.
__________________
UncleMacro is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 09:03 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82