Re: [Full-disclosure] FireFox Host: Buffer Overflow is not just exploitable on FireFox

From: Bipin Gautam (gautam.bipin_at_gmail.com)
Date: 09/17/05

  • Next message: Juha-Matti Laurio: "Re: [Full-disclosure] FireFox Host: Buffer Overflow is not just exploitable on FireFox"
    Date: Sat, 17 Sep 2005 19:44:09 +0545
    To: full-disclosure@lists.grok.org.uk
    
    

    On 9/14/05, Juha-Matti Laurio <juha-matti.laurio@netti.fi> wrote:
    > >Hi all,
    > >Research and development has let to a ~90% reliable working exploit for the
    > >IDN Heap Buffer overrun in FireFox on WinXP and Win2k3 as long as DEP is

    What? The exploit only works on winxp sp2 if DEP is turned off.....
    (or is it JUST there is another way in?) Your explanation is
    confusing!

    DEP That's turned ON by default... & most of us choose to turn it on
    for all service & softwares.

    -- 
    Bipin Gautam
    http://bipin.tk
    Zeroth law of security: The possibility of poking a system from lower
    privilege is zero unless & until there is possibility of direct,
    indirect or consequential communication between the two...
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/
    

  • Next message: Juha-Matti Laurio: "Re: [Full-disclosure] FireFox Host: Buffer Overflow is not just exploitable on FireFox"

    Relevant Pages

    • Re: DLL Funktion MoveMemory langsam?
      ... Zumindest habe ich das mal jmd. ... Athlon64 mit WinXP SP2 hat. ... An DEP hat er nix umgestellt, ...
      (microsoft.public.de.vb)
    • DEP preventing ce sdk from functioning
      ... there and the explanation was that DEP had disabled the driver because ... I'm not sure if DEP is necessary or if I can limit it ... My main worry is that disabling it could ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: Data Execution Prevention
      ... >Welcome to WinXP SP2, Chris! ... I'm familiar with DEP as introduced by SP2, and the issues with av, ... apps etc. that came with it, but I wasn't aware that subsequent ...
      (microsoft.public.windowsxp.general)
    • Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
      ... I did not ask to have an explanation about Heap based exploits. ... LS>I'm sure any HIPS would block it. ... DEP is turned on by default on all and every ...
      (Full-Disclosure)