Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]
- From: Sumit Siddharth <sumit.siddharth@xxxxxxxxx>
- Date: Tue, 3 Jan 2006 10:00:34 +0530
Dear All,
Sorry for the delayed response.
I had success in exploiting it remotely by a simple _javascript_
<script>window.open("http://aa...");</script>. But i think it doesnt work with some drivers.I am using XP ,professional, SP2. and firefox 1.0.6. I am using a string of about 53,000 char to overflow the buffer.
Thanks
Sumit
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Follow-Ups:
- References:
- [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]
- From: Sumit Siddharth
- Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]
- From: Lise Moorveld
- Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]
- From: Stan Bubrouski
- Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]
- From: ad@xxxxxxxxxxxxxxxx
- [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected]
- Prev by Date:
Re: [Full-disclosure] Antitoxin for "SQL Injection" (?) - Next by Date:
[Full-disclosure] WMF round-up, updates and de-mystification - Previous by thread:
Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected] - Next by thread:
Re: [Full-disclosure] Buffer Overflow vulnerability in Windows Display Manager [Suspected] - Index(es):
Relevant Pages
|