Windows ANI File Parsing Proof Of Concept (MS05-002)

From: Assaf (assaf404_at_YAHOO.COM)
Date: 01/12/05

  • Next message: Ivan Jones: "Running IE with decreased privileges"
    Date:         Wed, 12 Jan 2005 14:56:02 -0800
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Hi all!
    I have created a proof of concept for the Windows ANI File Parsing vulnerability which got published by eEye yesterday (MS05-002).

    Details about the proof of concept + demo can be found here :
    http://underwar.livedns.co.il/projects/ani/

    Very detailed process of creating the proof of concept :
    http://underwar.livedns.co.il/projects/ani/ani_poc.txt

    Assaf Reshef.

    __________________________________________________
    Do You Yahoo!?
    Tired of spam? Yahoo! Mail has the best spam protection around
    http://mail.yahoo.com

    --
    NTBugtraq Editor's Note:
    Most viruses these days use spoofed email addresses. As such, using an Anti-Virus product which automatically notifies the perceived sender of a message it believes is infected may well cause more harm than good. Someone who did not actually send you a virus may receive the notification and scramble their support staff to find an infection which never existed in the first place. Suggest such notifications be disabled by whomever is responsible for your AV, or at least that the idea is considered.
    --
    

  • Next message: Ivan Jones: "Running IE with decreased privileges"

    Relevant Pages

    • Re: What will you be hunting with this Fall?
      ... > a rear sight and a slightly prouder front sight than ... > add a forward sling loop and a sling button toward the ... > Do You Yahoo!? ... Mail has the best spam protection around ...
      (rec.hunting)
    • Re: Problem with kdvi font rendering after sarge-->etch upgrade
      ... I have no trouble opening these doucments on my ... Do You Yahoo!? ... Mail has the best spam protection around ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: Ousted
      ... South Korean PM played golf....result? ... asked him to resign. ... Do You Yahoo!? ... Mail has the best spam protection around ...
      (soc.culture.singapore)
    • Re: Duplicate disk in a volume group
      ... think this one would not be good because there is still an entry for a GOOD ... Duplicate disk in a volume group ... Do You Yahoo!? ... Mail has the best spam protection around ...
      (AIX-L)
    • RE: FreeBSD on Dell PE850
      ... When I install using the 6.1 disk one I get the error "Add of package ... Do You Yahoo!? ... Mail has the best spam protection around ... MailScanner thanks transtec Computers for their support. ...
      (freebsd-questions)