[Full-disclosure] Windows XP bug

BlackHawk hawkgotyou at gmail.com
Wed Jul 7 18:54:47 BST 2010


Hi list, i recently discovered a very small Windows XP bug, kind of
useless alone but that could be usefull in some scenarios.

Explanation:

when you try to access a non existing directory though shell command
"cd", XP returns an error (obviously), but if you cd to a non-existing
& move one directory up, you'll not get any error.

Example:
---
C:\>cd ./somerandomchars <-- Will give an error
Impossibile trovare il percorso specificato.

C:\>cd ./somerandomchars/../ <-- Everything is ok

C:\>
---

PoC on how to make this thing usefull:
http://www.scribd.com/doc/28080332/Podcast-Generator-1-3-Arbitrary-File-Download-Windows

Hope this could be useful for you in some way..

-- 
BlackHawk - hawkgotyou at gmail.com

Sent with Gmail



Full-Disclosure is hosted and sponsored by Secunia.