Search the archives!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: dave at immunityinc.com (Dave Aitel)
- Subject: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Date: Sun, 01 Apr 2007 15:42:17 -0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ASRL has limited entropy and the attacker can continue to try exploits an infinite number of times (as Solar Eclipse points out). This means you can write a reliable Vista exploit, theoretically. I'll probably finish one up on Monday. IE in protected mode would still allow you access to the local network and, more importantly, anything IE does. You could, for example, inject code into all viewed webpages that steals passwords and whatnot. Just at the very minimum. - -dave Larry Seltzer wrote: >>> It is completely possible to execute shellcode if we can do some DEP > bypass (ie. ret2libc attack, etc..) > > In Vista this should have problems because of ASLR, right? > > I'm beginning to think that web-based attacks with this in Vista aren't > really so scary. Even if you can get them to execute what can you really > do in IE protected mode? You need to get the user to run the ANI outside > of IE. Can anyone say what actually happens if you read an e-mail in the > Vista Mail program with an attack ANI embedded? > > Larry Seltzer > eWEEK.com Security Center Editor > http://security.eweek.com/ > http://blog.eweek.com/blogs/larry%5Fseltzer/ > Contributing Editor, PC Magazine > larryseltzer at ziffdavis.com > > _______________________________________________ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted and sponsored by Secunia - http://secunia.com/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGEAsYtehAhL0gheoRAutoAJ0QhPsOvcdCTU2dZZgkZYINC3+K3QCdFMQH UH02qnLi2Gbp07rLWpKv/5w= =4oC5 -----END PGP SIGNATURE-----
- Follow-Ups:
- [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Larry Seltzer
- [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- References:
- [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Larry Seltzer
- [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: dev code
- [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Larry Seltzer
- [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Prev by Date: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Next by Date: [Full-disclosure] April 1 joke
- Previous by thread: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Next by thread: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Index(es):