Visual Studio Pre and Post Build Settings Potential Exploitation

Visual Studio Pre and Post Build Settings Potential Exploitation

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Visual Studio Pre and Post Build Settings Potential Exploitation Ludovic Joly 12-20-2005
Posted by Ludovic Joly on December 20, 2005, 8:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Friends,

With the ever growing success of the open source software, it is
becoming very natural to import source code projects from various
sources and build them locally, especially in R&D or other high-tech
departments, and also in security concerned structures.

It occurred to me that an attack could be performed based on a Visual
Studio project. Pre and post build settings of a project could allow an
attacker to automatically run an executable file before or after a
build.

As a conclusion: one can only recommend the project is carefully
inspected before Build. Especially if the project comes from an
untrusted source.

Enjoy,
Ludovic Joly


Posted by Flash Gordon on December 20, 2005, 4:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Ludovic Joly wrote:
> Friends,
>
> With the ever growing success of the open source software, it is
> becoming very natural to import source code projects from various
> sources and build them locally, especially in R&D or other high-tech
> departments, and also in security concerned structures.
>
> It occurred to me that an attack could be performed based on a Visual
> Studio project. Pre and post build settings of a project could allow an
> attacker to automatically run an executable file before or after a
> build.

Anyone in a position to set up such an attack can is far more likely to
simply put something in the source.

> As a conclusion: one can only recommend the project is carefully
> inspected before Build. Especially if the project comes from an
> untrusted source.

Well, you should never trust anything from an untrusted source!
Seriously, if the source is one that might do an attack such as you are
suggesting you would have to do a thorough audit of the entire thing
anyway before making any use of it.
--
Flash Gordon
Living in interesting times.
Although my email address says spam, it is real and I read it.

Similar ThreadsPosted
private post December 12, 2005, 12:47 pm
Post your problem at www.innoengineer.com November 29, 2004, 8:01 pm
visual crypto readability December 16, 2004, 12:19 am
SSRT3472 rev.1 Potential unauthorized access with stmkfont April 8, 2004, 6:35 am
SSRT3472 rev.1 Potential unauthorized access with stmkfont May 17, 2004, 2:13 pm
SSRT3660 rev.3 DCE potential remote Denial of Service (DoS) January 20, 2005, 12:59 pm
SSRT3622 rev.1 Potential Security Vulnerabilities in HP WBEM Services for HP-UX June 7, 2005, 5:01 pm
SSRT3622 rev.2 Potential Security Vulnerabilities in HP WBEM Services for HP-UX June 10, 2005, 6:39 pm
SSRT4782 rev. 0 HP-UX CIFS Server potential remote root access July 28, 2004, 12:10 pm
SSRT4782 rev. 1 HP-UX CIFS Server potential remote root access August 5, 2004, 2:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy