• [^] # Re: Pas la première fois

    Posté par (site web personnel) . En réponse à la dépêche Clé web USB et sécurité. Évalué à 5.

    utilisation de vulnérabilité dans le "thumbnailer"

    c'est d'ailleurs un truc dans ce style qu'utilise le virus stuxnet qui est allé mettre le bordel en iran:

    instead of exploiting a vulnerability to forcibly execute an autorun.inf file, Stuxnet takes advantage of a vulnerability in parsing shortcut (.LNK) files in order to execute a malicious Control Panel module.

    An attacker can subvert this operation with a specially crafted .LNK file, which is pointed to a specially crafted Control Panel module (in reality, the malware). When the system attempts to resolve the shortcut file's icon, the vulnerability is triggered and the Control Panel module is automatically executed. The user does not need to click on the icon in order for the malware to be executed. ( http://www.f-secure.com/v-descs/trojan-dropper_w32_stuxnet.shtml )