On 4/2/07, Larry Seltzer <Larry@xxxxxxxxxxxxxxxx> wrote:

AS> A much simpler solution is to use heap spraying (which works fine on

AS> Vista) for systems that don't have DEP enabled.
TZ> Are we talking Sofware DEP or Hardware enforce DEP ?

Heap spraying implies running code in the heap,

Actually, um.. no.. it doesn't

which any DEP should
block. There are all kinds of software techniques that would detect heap
spraying. I'm sure any HIPS would block it.

Most likely not with regard to sotirov's new heap library stuff.

Larry Seltzer Security Center Editor
Contributing Editor, PC Magazine

How do you get to be in that position? Lot's of buzzword-tossing I'd have to
