/?pid=18629

Updated:12:30 PM EDT Apr 18


this is ggmania.com subsite NTFS Bug Allows Malicious Websites to Bluescreen Win7 /Win8.1 - TechAmok

NTFS Bug Allows Malicious Websites to Bluescreen Win7 /Win8.1 - [security]
04:16 PM EDT - May,26 2017 - post a comment

Russian site habrahabr.ru has a story up regarding how a new bug found in NTFS allows malformed filenames to bluescreen Windows 7 and 8.1 boxes. (Those of us not of unusual linguistic inclination can access an English version courtesy of Google Translate.) Apparently this issue is made worse by the fact that malicious websites can embed images using this malformed filename format, causing browsers to save it in their image cache and crash.
When an attempt is made to open a file relative to the $ mft file, the NtfsFindStartingNode function will not find it, because This function performs a search somewhat differently, in contrast to the function NtfsOpenSubdirectory, which finds this file always. Therefore, the loop starts from the root of the file system. Next, the function NtfsOpenSubdirectory will open this file and grab it ERESOURCE exclusively. At the next iteration, the loop will find that the file is not a directory, and therefore will interrupt its operation with an error. And at the end of its work function NtfsCommonCreate through the function NtfsTeardownStructures will try to close it. Function NtfsTeardownStructures, in turn, will face the fact that it can not close the file, because It is opened by the file system itself when it is mounted. In this case, contrary to the expectations of the NtfsCommonCreate function, the NtfsTeardownStructures function will not free the ERESOURCE $ mft file. Thus, he will remain captured forever. Therefore, for example, when you try to create a file or read a volume file, the NTFS file system will try to grab the ERESOURCE $ mft file and hang at this stage forever.


Add your comment (free registrationrequired)

Short overview of recent news articles

Apr,18 2024 Radeon RX 5700 XT vs. 7700 XT, 2024 Revisit
Apr,18 2024 I Will Build You a PC Right Now!
Apr,17 2024 These games carry REAL security risks! BEWARE!
Apr,17 2024 Visible First to Offer Annual Payment Plan, with Discount up to 26%
Apr,17 2024 Is Coding Still Worth Learning in 2024?
Apr,17 2024 All New Atlas - Boston Dynamics
Apr,16 2024 The NEW Chip Inside Your Phone! (NPUs)
Apr,16 2024 XPS 14 vs 14" MacBook Pro - Apple just KILLED Intel!
Apr,15 2024 The Most 2024 Laptop - Razer Blade 14 Review
Apr,15 2024 NEVER install these programs on your PC... EVER!!!
Apr,14 2024 Use Live Translate on Galaxy S24 series to translate a call's
Apr,14 2024 I Tried a Non-Invasive Blood Sugar Watch. Miracle or Scam?
Apr,13 2024 Samsung Galaxy Ring - This Just Got Interesting
Apr,13 2024 Piracy Is Over Party - WAN Show April 12, 2024
Apr,13 2024 Conan O'Brien Needs a Doctor While Eating Spicy Wings
Apr,13 2024 Beatbox Jcob recreats every sound
Apr,13 2024 Intel is Gunning for NVIDIA
Apr,13 2024 Building a Budget DIY Home Surveillance System
Apr,12 2024 Lenovo Yoga Buyers Guide - What's the Best Thin and Light Laptop
Apr,11 2024 DARK MATTER Trailer (2024) New Sci-Fi Movies 4K
Apr,11 2024 How to Build a PC, the last guide you'll ever need! (2024 Update)
Apr,10 2024 Intel 300 CPU Review - The Pentium Replacement is Finally Here...
Apr,10 2024 Wubuntu, the Dubious Linux Windows
Apr,09 2024 A Lite Version Of Windows 11 To Be Released This Year
Apr,09 2024 This $150 Smartphone might be All You Need
Apr,09 2024 I Can't Believe These are Real - Reacting to Ridiculous PCs on
Apr,08 2024 A new video shows AirPower prototype charging an Apple Watch
Apr,08 2024 Google Deleting Incognito Data, Intel $7B Foundry Loss, $350+ Curved
Apr,08 2024 20 COOL GADGETS YOU SHOULD SEE
Apr,08 2024 New HTTP/2 vulnerability leaves servers in danger of devastating DoS
Apr,07 2024 3D Printed PC Fan Test: Does the Anti-Stall Ring Boost Performance?
Apr,06 2024 The Greatest GPU of All Time: NVIDIA GTX 1080 Ti & GTX 1080 2024
Apr,06 2024 Top NEW RELEASES on Netflix in APRIL 2024
Apr,05 2024 Magician vs Slow-Mo Camera (Skill Challenge)
Apr,05 2024 Re-Ranking All Current GPUs From Worst to Best (2024 Update)
Apr,04 2024 Ripple to ISSUE STABLE COIN utilizing XRP AUTO-Bridging Function
Apr,04 2024 HW News - Intel Battlemage Appears, Open Source GPU, Xbox Handheld
Apr,03 2024 Vivo X Fold 3 Pro Hands-On: The New Best Foldable Hardware
Apr,02 2024 OPNSense: Protect Your Home LAN With a Transparent Filtering Bridge
Mar,31 2024 Ultimate Guide to Virtualization: Run MacOS, Linux, and Windows all
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs