Dmitry Yu wrote: > > Being curious, on Win2k, I copied cmd.exe (from > winnt\system32) as xyz.pif; > > then (right-click) Properties, Program crashes explorer. Is > this related to > > IconHandler, and is it exploitable? > > Disassembly window shows that there was an attempt to read dword > at [EAX] (EAX=0). So at first glance this doesn't seem to be > trivially > exploitable, but I'm not a win32 expert, and intuition > suggests that there > must be a way. One possible exploit is to simply place the file on your desktop. explorer.exe goes to 100% cpu. Curt Purdy CISSP, GSEC, MCSE+I, CNE, CCDA Information Security Engineer DP Solutions ---------------------------------------- If you spend more on coffee than on IT security, you will be hacked. What's more, you deserve to be hacked. -- former White House cybersecurity adviser Richard Clarke