Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]



Dear All,
Sorry for the delayed response.
I  had success in exploiting it remotely by a simple _javascript_
<script>window.open("http://aa...");</script>. But i think it doesnt work with some drivers.I am using XP ,professional, SP2. and firefox 1.0.6. I am using a string of about 53,000 char to overflow the buffer.
Thanks
Sumit

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/