Recently, this vulnerability is very popular. In short, it is a malicious constructed shortcut that can execute file code.Only a few learning skills + limited time, the specific content will not talk about, just put some connections up.
Symantec's worm report:
Http://www.symantec.com/connect/blogs/w32temphid-usb
Vulnerability Generation Process Analysis:
Aspx ">Http://community.websense.com/blogs/securitylabs/archive/2010/07/20/microsoft-lnk-vulnerability-brief-technical-analysis-cve-2010-2568.aspx
Exploit-db Vulnerability Report and POC:
Http://www.exploit-db.com/exploits/14403/
SRP defense policy:
Http://blog.didierstevens.com/2010/07/20/mitigating-lnk-exploitation-with-srp/
Didiersteven S's own software Ariad defense policy:
Http://blog.didierstevens.com/2010/07/18/mitigating-lnk-exploitation-with-ariad/
Microsoft Vulnerability reporting and impact environment:
Http://www.microsoft.com/technet/security/advisory/2286198.mspx
Monyer