Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: "Larry Seltzer" <Larry@xxxxxxxxxxxxxxxx>
- Date: Mon, 2 Apr 2007 10:06:21 -0400
AS> A much simpler solution is to use heap spraying (which works fine on
AS> Vista) for systems that don't have DEP enabled.
TZ> Are we talking Sofware DEP or Hardware enforce DEP ?
Heap spraying implies running code in the heap, which any DEP should
block. There are all kinds of software techniques that would detect heap
spraying. I'm sure any HIPS would block it. But like DEP they're not on
in Windows by default.
Larry Seltzer
eWEEK.com Security Center Editor
http://security.eweek.com/
http://blog.eweek.com/blogs/larry%5Fseltzer/
Contributing Editor, PC Magazine
larryseltzer@xxxxxxxxxxxxx
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
- Follow-Ups:
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Thierry Zoller
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Jason Areff
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- References:
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Larry Seltzer
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: dev code
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Larry Seltzer
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Dave Aitel
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Larry Seltzer
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Alexander Sotirov
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- From: Thierry Zoller
- Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Prev by Date: Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Next by Date: Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Previous by thread: Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Next by thread: Re: [Full-disclosure] Windows .ANI LoadAniIcon Stack Overflow
- Index(es):
Relevant Pages
|