Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow



It is completely possible to execute shellcode if we can do some DEP
bypass (ie. ret2libc attack, etc..)

In Vista this should have problems because of ASLR, right?

I'm beginning to think that web-based attacks with this in Vista aren't
really so scary. Even if you can get them to execute what can you really
do in IE protected mode? You need to get the user to run the ANI outside
of IE. Can anyone say what actually happens if you read an e-mail in the
Vista Mail program with an attack ANI embedded?

Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blog.eweek.com/blogs/larry%5Fseltzer/
Contributing Editor, PC Magazine
larryseltzer@xxxxxxxxxxxxx

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • RE: "Attempted to read or write protected memory" on some vista machin
    ... This may be due to ASLR and DEP on Vista. ... would produce different IL on different machines? ...
    (microsoft.public.dotnet.framework.interop)
  • [Full-disclosure] ASLR now built into Vista
    ... Address Space Layout Randomization is now part of Vista as of beta 2. ... I wrote about ASLR on the Windows platform back in September last year and noted that unless you rebase the image exe then little is added. ... ASLR in Vista solves this so remote exploitation of overflows has just got a lot harder. ...
    (Full-Disclosure)
  • ASLR now built into Vista
    ... Address Space Layout Randomization is now part of Vista as of beta 2. ... I wrote about ASLR on the Windows platform back in September last year and noted that unless you rebase the image exe then little is added. ... ASLR in Vista solves this so remote exploitation of overflows has just got a lot harder. ...
    (Bugtraq)
  • Re: [Full-disclosure] ASLR now built into Vista
    ... noted that unless you rebase the image exe then little is added. ... ASLR in Vista solves this so remote exploitation of overflows has just got a ... I haven't looked at Vista yet:) ...
    (Full-Disclosure)
  • Re: [Full-disclosure] ASLR now built into Vista
    ... noted that unless you rebase the image exe then little is added. ... ASLR in Vista solves this so remote exploitation of overflows has just got a ... I haven't looked at Vista yet:) ...
    (Bugtraq)