Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]



Dear All,
Sorry for the delayed response.
I  had success in exploiting it remotely by a simple _javascript_
<script>window.open("http://aa...");</script>. But i think it doesnt work with some drivers.I am using XP ,professional, SP2. and firefox 1.0.6. I am using a string of about 53,000 char to overflow the buffer.
Thanks
Sumit

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


















Relevant Pages

  • Closure scope confusion
    ... I'm currently trying to get a script (http://bitbucket.org/codethief/ ... executes the JavaScript code in HTML data received over AJAX ... # 'success': this.load_html ...
    (comp.lang.javascript)
  • Re: Causing File Download on Page Load
    ... JavaScript expert/author who has so far produced ... but your long and frequent posts about it are out of place here and ... Resig copies me when he can, ... the same success with your book as you have with "your" library. ...
    (comp.lang.javascript)
  • Re: Causing File Download on Page Load
    ... JavaScript expert/author who has so far produced nothing except for an unsuccessful javaScript library called "My Library" (even though it is not "your" library because the code in it is taken from the "Code Worth Recommending" project). ... I have never looked a jQuery and don't intend to, but your long and frequent posts about it are out of place here and only make it clear to me how jealous you are of Resig because of the success of his library. ... I think that "your" industry could manage very well without you. ...
    (comp.lang.javascript)
  • Re: No Right Click Code
    ... the body, it works on preview of my html editor, but when I try it in the ... default browserit doesnt work? ... Maybe javascript is turned off in IE? ... The ULTIMATE Windoze Fanboy: ...
    (microsoft.public.windowsxp.general)
  • How to use JSException (attributes and methods)
    ... I've been doing a bit of Java Applet to JavaScript communication through ... JSObject.callrecently and am having much success. ... catching exceptions that were thrown I am not ...
    (comp.lang.java.programmer)