logoalt Hacker News

azalemethtoday at 2:59 PM3 repliesview on HN

This all sounds like a wonderful way to write some truly annoying malware. I expect to see hidden mounts on SQL-escape-type-maliciously-named drives soon...


Replies

Someone1234today at 4:34 PM

I understand your point; but I'm struggling to see how this could be weaponized. Keep in mind, that these Dos compatible drive letters need to map to a real NT path endpoint (e.g. a drive/volume); so it isn't clear how the malware could both have a difficult to scan Dos tree while also not exposing that same area elsewhere for trivial scanning.

show 3 replies
ahokatoday at 5:09 PM

Wait until your learn about Alternate Data Streams…

show 2 replies
hulitutoday at 4:31 PM

> This all sounds like a wonderful way to write some truly annoying malware.

AFAIK you need admin priviledges to play with drives in Windows.