[TOOL] .NETMon - .NET Flow Tracing

From: SecuriTeam (support_at_securiteam.com)
Date: 05/17/05

  • Next message: SecuriTeam: "[NT] Willings WebCam Plain Text Password"
    To: list@securiteam.com
    Date: 17 May 2005 11:14:01 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      .NETMon - .NET Flow Tracing
    ------------------------------------------------------------------------

    SUMMARY

    DETAILS

    The information from .NET hooks can be used to build tools capable of
    analyzing code timings, exception handling, and memory usage. Foundstone's
    interest in the profiling API was to develop a flow analysis tool that
    gives auditors the capability of following the flow of function calls to
    better understand the code execution and ferret out the vulnerabilities
    that may exist in the application.

    Flow tracing is a useful part of application debugging and analysis. For
    every test case written to check the reliability of the code, the ability
    to follow the execution flow and check for code coverage seems to be of
    immense value to developers, debuggers, and testers. Foundstone introduces
    NETMon to equip developers and debuggers with a tool which will allow
    them do organized flow tracing of applications and to identify security
    loopholes.

    The profiling APIs do not require any code additions or modification which
    eliminates any changes needed to profile an application. Its event driven
    design allows the definition of the events that should be sent to the
    'listener' application. With the current version, there is some
    performance impact because the events are being monitored by the
    FunctionEnter and FunctionLeave hooks which are fired for each Managed
    Method executed by the CLR. This issue will be addressed in the next
    version of .NETMon which will resolve the function's signature (return
    type, namespace, method name and parameters) asynchronously.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:mark.curphey@foundstone.com>
    Curphey, Mark.
    To keep updated with the tool visit the project's homepage at:
    <http://www.foundstone.com> http://www.foundstone.com

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NT] Willings WebCam Plain Text Password"

    Relevant Pages

    • [NT] Defeating Microsoft Windows XP SP2 Heap Protection and DEP Bypass
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... and bypassing DEP (Data Execution Prevention). ... Buffer overrun attacks are among the most common mechanisms, or vectors, ... a long string to an input stream or control longer than the memory ...
      (Securiteam)
    • [NT] Windows VDM #UD Local Privilege Escalation
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... vulnerability to fully compromise a Windows NT 4.0, Windows 2000, Windows ... 32-bit VDM "host" code, and the invalid opcode fault handler within the ... process).The kernel does not validate the address to which execution is ...
      (Securiteam)
    • [UNIX] Rssh and Scponly Arbitrary Command Execution
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... are designed to allow execution only of certain preset programs. ... command execution on the remote host is possible. ... rssh allows any of five predefined programs to be executed on the remote ...
      (Securiteam)
    • [NEWS] ClamAV libclamav MEW PE File Integer Overflow Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... ClamAV libclamav MEW PE File Integer Overflow Vulnerability ... Remote exploitation of an integer overflow vulnerability in Clam ... Exploitation of this vulnerability results in the execution of arbitrary ...
      (Securiteam)
    • [NT] Microsoft Windows Task Scheduler .job Stack Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... code execution flow to an address of their choosing. ... executed by exploiting this flaw will be run with the privileges of the ... In the case of Internet Explorer, ...
      (Securiteam)