Re: [Full-disclosure] Microsoft FTP Client Multiple Bufferoverflow Vulnerability



Tonnerre Lombard ha scritto:
Isn't the FTP client compiled with stack overflow protection?
If so, how is that supposed to help?
By terminating the program before the payload is executed
May I suggest that this protection is not perfect? I was hoping that
people on this mailing list consider this to be an established fact.

You can suggest it. However, ftp.exe is also linked with the secure
exception handlers option. How do you divert execution when ftp.exe is
running on a platform with encrypted global pointers? ftp.exe is no
Internet Explorer, either, you cannot arbitrarily load third party DLLs
in it. Why, it doesn't even link shell32.dll or ole32.dll. And I remind
you these are buffer overflows in a text field of an user interface

Rajesh and others like him have been peddling this "vulnerability" for
months if not years. Some security "professionals" should stop fooling
themselves and have the basic honesty to admit their behavior is rather
more fitting of a small-time loan shark or mafia picciotto, if not the
honesty to submit straight away to the vendor what is clearly just a bug
with no strategical security implications

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Validy Technology: A program protection method that really works.
    ... Validy Technology is a program protection method. ... correct execution of the program inside this coprocessor. ... The secure coprocessor uses a silicon chip which can take several ...
    (comp.arch)
  • Validy Technology: A program protection method that really works.
    ... Validy Technology is a program protection method. ... correct execution of the program inside this coprocessor. ... The secure coprocessor uses a silicon chip which can take several ...
    (comp.security.misc)
  • Validy Technology: A program protection method that really works.
    ... Validy Technology is a program protection method. ... correct execution of the program inside this coprocessor. ... The secure coprocessor uses a silicon chip which can take several ...
    (alt.computer.security)
  • Re: Attention Windows Users
    ... > So if the compiler were written to automatically include code for ... languages) that have built-in data integrity support, ... including software and hardware based protection for code execution of data. ...
    (rec.aviation.piloting)
  • Re: DEP and hardware
    ... >> level DEP (Data ... > You mean that thing that stops code execution in the section of the ... > the motherboard has this protection, and hence canot run win98 (or ... DEP IS a feature of the CPU. ...
    (microsoft.public.windowsxp.help_and_support)