Welcome to MSDN Blogs Sign in | Join | Help

Browse by Tags

All Tags » Fixing LUA Bugs   (RSS)

LUA Buglight 2.1 released

LUA Buglight 2.1, identifies admin-permissions issues ("LUA bugs") in desktop applications. New version supports Windows 7 (x86 and x64), Vista (x86 and x64), XP (x86 only) and corresponding Server OSes.

LUA Buglight

LUA Buglight 2.1, identifies admin-permissions issues ("LUA bugs") in desktop applications. New version supports Windows 7 (x86 and x64), Vista (x86 and x64), XP (x86 only) and corresponding Server OSes.

"LUA Bug" demo app

A simple VB6 app to demonstrate "LUA bugs" - useful for testing tools and remediation techniques. Source code provided.
Posted by Aaron Margosis | 4 Comments
Attachment(s): LuaBugs_VB6.zip

LUA Buglight 2.0, second preview

Second Preview Version of LUA Buglight 2.0 -- a utility to identify admin-permissions-required issues in desktop applications
Posted by Aaron Margosis | 11 Comments
Attachment(s): LuaBuglight.zip

LUA Buglight 2.0 - preview

LUA Buglight 2.0 - preview version available for download

LUA Buglight updated information

Updated information about LUA Buglight.

MSDN webcast: LUA Buglight

I'll be presenting an MSDN webcast and demoing LUA Buglight next Tuesday, October 17, 2006, 11:00am US Pacific time. Click here for more information and to register. Make sure to install the Microsoft LiveMeeting client prior to showtime. [Update, 18

LUA Buglight public [pre]-release

"Why does Application XYZ need to run as admin?"

"Problems of Privilege: Find and Fix LUA Bugs" in TechNet Magazine

"Problems of Privilege: Find and Fix LUA Bugs" published in TechNet Magazine.

Changing access control on folders vs. files

More info on the risks of changing access control lists to fix LUA bugs.

Fixing "LUA Bugs", Part II

A systematic approach for working around LUA bugs that avoids unnecessary exposure - "the rest of the story"

Fixing "LUA bugs", Part I

A systematic approach for working around LUA bugs that avoids unnecessary exposure

What is a "LUA Bug"? (And what isn't a LUA bug?)

Not every "access denied" indicates a LUA bug!
 
Page view tracker